• PATCH AVAILABLE

CVE-2026-62916: pre-auth authentication bypass in Microsoft Microsoft Entra

An unauthenticated attacker can bypass authentication in Microsoft Entra to elevate privileges over the network, allowing full confidentiality, integrity, and availability impact. CVE-2026-62916 is an authentication-bypass flaw (CWE-288) in Microsoft Entra; vendor guidance lists the issue but does not specify fixed versions in the published affected data. Exploitation requires network access and does not require prior valid credentials or user interaction according to the supplied analysis.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00865
CWE
CWE-288
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw allows privilege elevation without prior credentials, so immediately restrict network exposure to Microsoft Entra endpoints and follow Microsoft’s mitigation and patch guidance.

What is CVE-2026-62916?

An unauthenticated attacker can bypass authentication in Microsoft Entra to elevate privileges over the network, allowing full confidentiality, integrity, and availability impact. CVE-2026-62916 is an authentication-bypass flaw (CWE-288) in Microsoft Entra; vendor guidance lists the issue but does not specify fixed versions in the published affected data. Exploitation requires network access and does not require prior valid credentials or user interaction according to the supplied analysis. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft Entra are affected?

BRANCHAFFECTEDFIXED
Microsoft Entra-

Is CVE-2026-62916 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-62916

  1. Follow Microsoft’s published guidance and apply vendor patches or updates as they become available.
  2. Restrict network access to Entra endpoints to trusted management networks and block unnecessary internet exposure.
  3. Increase logging and monitoring for anomalous authentication or privilege elevation events in Microsoft Entra.
  4. Implement compensating controls such as conditional access and MFA where possible while a patch is applied.

Frequently asked questions

Is CVE-2026-62916 being actively exploited?

There are no public reports of exploitation of CVE-2026-62916 as of 2026-09-30.

Which Microsoft Entra versions are affected by CVE-2026-62916?

Published affected data for Microsoft Entra does not specify exact version ranges or fixed releases in the supplied facts.

Is there a patch for CVE-2026-62916?

Vendor guidance exists and a patch is reported available; the supplied facts do not list specific fixed version identifiers.

Does CVE-2026-62916 require authentication?

No; CVE-2026-62916 is described as an authentication bypass that enables privilege elevation without prior valid credentials.

References