Entra ID SSRF allows spoofing (CVE-2026-35431)
CVE-2026-35431
CVE-2026-35431 (CVSS 10.0) SSRF in Microsoft Entra ID Entitlement Management lets unauthenticated attackers spoof network identities and access internal resources. Update to the latest patched Entra ID version now.
Patch now - CVE-2026-35431 is a critical server-side request forgery (SSRF) in Microsoft Entra ID Entitlement Management that lets unauthenticated attackers spoof network identities and access internal resources. Apply Microsoft’s security patch immediately, as no workarounds exist.
Overview
CVE-2026-35431 is a critical server-side request forgery (SSRF) vulnerability in Microsoft Entra ID Entitlement Management that allows an unauthenticated attacker to perform network-level spoofing. With a CVSS score of 10.0, this is the maximum severity rating, reflecting the combination of network-based attack vector, low complexity, and no required privileges or user interaction.
Technical Details
The vulnerability exists in how Entra ID Entitlement Management handles outbound network requests. An attacker can craft requests that cause the service to make unauthorized requests to internal or external systems. By exploiting this SSRF, the attacker can impersonate legitimate network resources or services, enabling spoofing attacks against other systems connected to the affected Entra ID environment.
Key characteristics:
- Attack Vector: NETWORK (remotely exploitable)
- Attack Complexity: LOW (no special conditions required)
- Privileges Required: NONE (no authentication needed)
- User Interaction: NONE (no victim action required)
Impact
Successful exploitation could allow an unauthorized attacker to:
- Spoof network identities and services
- Access internal resources that should be isolated
- Potentially pivot to other systems within the network
The CVSS 10.0 score indicates this is as severe as a vulnerability can be rated. While not currently confirmed as actively exploited, the lack of required authentication and user interaction means automated attacks are feasible.
Affected Versions
This vulnerability affects Microsoft Entra ID Entitlement Management components. Organizations using Entra ID (formerly Azure Active Directory) with entitlement management features should verify their deployment status.
Remediation
Microsoft has released security updates addressing this vulnerability. Apply patches immediately:
- Install the latest Entra ID update from the Microsoft Security Response Center
- Verify update deployment across all affected tenants
- Review network logs for signs of suspicious outbound requests
No workarounds are currently available; patching is the only complete mitigation.
Security Insight
This vulnerability reveals a dangerous pattern in identity management platforms: SSRF flaws in systems that handle authentication and authorization can undermine the entire trust model of an organization’s identity infrastructure. As cloud identity providers become more feature-rich with entitlement management, access reviews, and automated provisioning, the attack surface expands. Microsoft must treat these components with the same security rigor as core authentication services, because a flaw in entitlement management can enable spoofing that bypasses all downstream security controls.
Related reading: Recent attacks show how identity infrastructure vulnerabilities are being exploited - see APT28 DNS Hijacking targeting Microsoft 365 credentials and China-linked Storm-1175 using zero-days to deploy Medusa ransomware. Our weekly threat roundup covers these and other developments.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has be...
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network....
Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API c...
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network....