Description
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Published: 2026-08-20
Score: 10 Critical
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Untrusted data is deserialized by Microsoft Entra ID without adequate validation, enabling an attacker to inject malicious object data that is executed upon processing. The flaw is a classic deserialization vulnerability (CWE‑502). The outcome is that any code supplied by the attacker can run with the privileges of the Entra ID process, potentially compromising user accounts, data, or the entire identity platform. The description indicates a direct code execution impact with no mention of limited scope or restrictions.

Affected Systems

Microsoft Entra ID, a Microsoft product used for identity and access management. The exact affected versions are not listed in the data provided, so any installation of Microsoft Entra ID without a recent update should be considered vulnerable until proven otherwise.

Risk and Exploitability

The CVSS score of 10 underscores a critical severity, and the EPSS score of 1% indicates a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver malicious serialized data to an Entra ID endpoint over the network; the description suggests a remote, network‑based vector. Since no mitigation steps from Microsoft are specified in the entry, the risk remains high pending a vendor patch.

Generated by OpenCVE AI on August 21, 2026 at 19:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Microsoft for the latest security update or patch for Entra ID and apply it immediately.
  • If a patch is not yet available, restrict network traffic to Entra ID services to only trusted sources and monitor for anomalous traffic patterns.
  • Validate or sanitize any data received by Entra ID before deserialization, and if possible disable or restrict any feature that accepts external serialized objects.

Generated by OpenCVE AI on August 21, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft entra Id
CPEs cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*
Vendors & Products Microsoft entra Id

Fri, 21 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-21T00:00:00+00:00', 'dueDate': '2026-08-24T00:00:00+00:00'}


Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-08-21T00:00:00+00:00', 'dueDate': '2026-08-24T00:00:00+00:00'}


Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Title Microsoft Entra ID Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft microsoft Entra Id
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:microsoft_entra_id:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Entra Id
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Entra Id Microsoft Entra Id
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:34:40.607Z

Reserved: 2026-08-03T22:51:46.190Z

Link: CVE-2026-69836

cve-icon Vulnrichment

Updated: 2026-08-21T15:33:42.806Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:18:00.740

Modified: 2026-08-25T16:08:43.290

Link: CVE-2026-69836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:00:13Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data