Description
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-05-12
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 15 May 2026 18:00:00 +0000

Type Values Removed Values Added
Title Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability Azure Entra ID Spoofing Vulnerability
First Time appeared Microsoft microsoft Entra Id
CPEs cpe:2.3:a:microsoft:azure_enterprise_security_token_service:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:microsoft_entra_id:*:*:*:*:*:*:*:*
Vendors & Products Microsoft microsoft Entra Id

Tue, 12 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Enterprise Security Token Service (ESTS) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft azure Enterprise Security Token Service
Weaknesses CWE-200
CPEs cpe:2.3:a:microsoft:azure_enterprise_security_token_service:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Enterprise Security Token Service
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Enterprise Security Token Service Microsoft Entra Id
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-15T17:13:45.407Z

Reserved: 2026-04-11T23:06:15.615Z

Link: CVE-2026-40379

cve-icon Vulnrichment

Updated: 2026-05-12T19:08:57.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-12T18:17:16.663

Modified: 2026-05-13T15:34:52.573

Link: CVE-2026-40379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T22:30:05Z

Weaknesses