← Terug naar overzicht

CVE-2026-69851 describes a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Active Directory. The flaw allows an authorized attacker to elevate privileges over a network by exploiting the SSRF weakness. The vulnerability requires the attacker to already have some level of authorization, making it an elevation of privilege issue rather than an unauthenticated attack. Microsoft has published guidance through its Security Response Center (MSRC). The vulnerability is tracked by NVD at NIST and carries a high criticality rating. Organizations using Azure Active Directory should review the Microsoft advisory and apply any available mitigations or patches promptly.

Affected products

  • Azure Active Directory

Related CVE's

  • CVE-2026-69851

Categories

  • Cloud & Virtualization
  • Identity & Access