VYPR
advisoryPublished Sep 9, 2026· 1 source

Microsoft Azure Entra ID OAuth Vulnerability Exposes Sensitive Information

A critical vulnerability in Microsoft Azure Entra ID's OAuth Device Code Grant allows unauthenticated remote attackers to disclose sensitive organizational information.

A newly disclosed vulnerability within Microsoft Azure's Entra ID service, specifically affecting its OAuth Device Code Grant functionality, poses a risk of sensitive information disclosure. The flaw, identified by Zero Day Initiative (ZDI) as ZDI-26-629, allows remote attackers to access internal organizational data without requiring any authentication.

The vulnerability stems from the way error messages are generated within the OAuth Device Code Grant endpoint. Attackers can exploit this by triggering specific error conditions that inadvertently reveal internal details associated with arbitrary Entra ID tenants. This could potentially expose information that aids in further reconnaissance or compromises the security posture of affected organizations.

Zero Day Initiative has assigned a CVSS score of 5.8 to this vulnerability, categorizing it as medium severity. While not reaching the critical threshold, the lack of authentication required for exploitation and the potential for sensitive data exposure make it a significant concern for organizations utilizing Azure Entra ID for identity and access management.

Microsoft has addressed this vulnerability by releasing a patch. The fix is included in version 2.1.24394.0 of the relevant component. Users are strongly advised to update to this version or later to mitigate the risk of exploitation.

The disclosure timeline indicates that the vulnerability was first reported to Microsoft on March 31, 2026. Following a coordinated disclosure process, the advisory was publicly released on September 9, 2026, with an update to the advisory also occurring on the same day.

This vulnerability was discovered by Nelson William Gamazo Sanchez of TrendAI Research. The Zero Day Initiative, known for its proactive approach to identifying and facilitating the patching of software vulnerabilities, published the advisory to inform the public and encourage timely remediation.

Organizations using Microsoft Azure Entra ID should prioritize applying the available security updates. The ability for unauthenticated attackers to glean internal information underscores the importance of maintaining up-to-date security configurations and promptly addressing disclosed vulnerabilities, even those not classified as critical.

The disclosure of ZDI-26-629 highlights a recurring theme in cloud security: the potential for misconfigurations or coding errors in authentication and authorization flows to lead to unintended data exposure. Continuous monitoring and prompt patching remain essential defenses against such threats.

Synthesized by Vypr AI