Tuesday, July 15, 2025
HomeNewsMicrosoft Entra ID vulnerability allows full account takeover – and takes barely...

Microsoft Entra ID vulnerability allows full account takeover – and takes barely any effort

Microsoft Entra ID vulnerability allows full account takeover – and takes barely any effort


  • 10% of the 150,000+ SaaS apps on offer could be affected by Entra ID vulnerability
  • It was first disclosed in 2023, but many apps still remain affected
  • App vendors need to issue patches or you risk account takeover

Semperis has released new research uncovering a severe flaw in Microsoft‘s Entra ID, called nOAuth, and its effects could span 10% of SaaS applications globally.

The vulnerability involves a cross-tenant authentication flaw affecting Entra ID integrations – attackers could execute full account takeover with just access to an Entra tenant and the victim’s email.

Source

Author

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular