May 2026: Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-42901 Published on May 22, 2026
Microsoft Entra ID Elevation of Privilege Vulnerability
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Weakness Type
Origin Validation Error
The software does not properly verify that the source of data or communication is valid.
Products Associated with CVE-2026-42901
Want to know whenever a new CVE is published for Microsoft Entra Id? stack.watch will email you.
Affected Versions
Microsoft Entra Version - is affected by CVE-2026-42901Exploit Probability
EPSS
0.30%
Percentile
22.34%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.