A critical combination of legacy components could have allowed complete access to the Microsoft Entra ID tenant of every ...
July 17, 2025; CVSS 10.0 Entra ID bug via legacy Graph enabled cross-tenant impersonation risking tenant compromise.
The Register on MSN
One token to pwn them all: Entra ID bug could have granted access to every tenant
Until Microsoft lobbed it into a virtual volcano A security researcher claims to have found a flaw that could have handed him ...
A Dutch security researcher has published an indepth analysis of a critical vulnerability that could have allowed attackers ...
A Dutch researcher found a flaw in Microsoft Entra ID that could expose every tenant worldwide. Microsoft patched it within ...
Dutch security researcher Dirk-jan Mollema discovered a critical vulnerability in Microsoft Entra ID that allowed full access ...
Though patched, the flaw underscores systemic risks in cloud identity systems where legacy APIs and invisible delegation ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results