Skip to content

Add CVE-2026-26148: Azure Entra ID Privilege Escalation - #475

Open
vanhoangkha wants to merge 1 commit into
wiz-sec:mainfrom
vanhoangkha:contribution/cve-2026-26148-entra-id-privesc
Open

Add CVE-2026-26148: Azure Entra ID Privilege Escalation#475
vanhoangkha wants to merge 1 commit into
wiz-sec:mainfrom
vanhoangkha:contribution/cve-2026-26148-entra-id-privesc

Conversation

@vanhoangkha

Copy link
Copy Markdown

Summary

Adds CVE-2026-26148 — Azure Entra ID External Initialization Privilege Escalation.

  • Severity: HIGH
  • Platform: Azure
  • Service: Entra ID
  • Published: 2026/03/11

External initialization of trusted variables or data stores allows unauthorized privilege escalation.

References

External initialization of trusted variables allows unauthorized
attacker to elevate privileges locally in Azure Entra ID.

Severity: HIGH
Patched server-side by Microsoft.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant