May 2026: Microsoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-42901 Published on May 22, 2026

Microsoft Entra ID Elevation of Privilege Vulnerability
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

Origin Validation Error

The software does not properly verify that the source of data or communication is valid.


Products Associated with CVE-2026-42901

Want to know whenever a new CVE is published for Microsoft Entra Id? stack.watch will email you.

 

Affected Versions

Microsoft Entra Version - is affected by CVE-2026-42901

Exploit Probability

EPSS
0.30%
Percentile
22.34%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.