CVE-2026-59115

9.9

Microsoft · Microsoft Entra Provisioning Service

A path traversal flaw in the SyncFabric component of Microsoft Entra Provisioning Service allows an authorized attacker to elevate privileges over a network.

Executive summary

A critical path traversal vulnerability in the Microsoft Entra Provisioning Service allows an authenticated attacker to escalate privileges and compromise system integrity.

Vulnerability

The vulnerability resides in the SyncFabric component and stems from the improper neutralization of path traversal sequences (specifically the ".../...//" pattern). An authenticated attacker can exploit this to access unauthorized paths, leading to privilege escalation.

Business impact

The CVSS score of 9.9 underscores the extreme risk posed by this vulnerability. By escalating privileges, an attacker could potentially gain control over the provisioning process, leading to the unauthorized creation or modification of accounts and the compromise of integrated cloud services.

Remediation

Immediate Action: Microsoft has deployed a service-side update to the latest version of the Entra Provisioning Service to address this flaw.

Proactive Monitoring: Review logs for the SyncFabric component to identify any attempts to use traversal sequences or unauthorized access patterns.

Compensating Controls: Utilize identity governance tools to monitor and alert on any unexpected changes to account provisioning states or unusual administrative actions.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability, it is imperative to ensure that all Entra Provisioning Service configurations are aligned with the latest security standards provided by Microsoft. Organizations should prioritize a review of their provisioning workflows to ensure no malicious activity has been facilitated by this oversight.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Fix documented per CVE record

Sources