← Back to browse · API

CVE-2026-57100

Severity
CRITICAL
CVSS
9.9
EPSS
0.00653
Risk score
39.83
CISA KEV
No
PoC
No
Published
2026-07-02
Modified
2026-08-14
First seen
2026-08-07
Aliases
EUVD-2026-41442, GHSA-29V8-Q543-PF5W
Products
Microsoft:Microsoft Entra Provisioning Service -
Sources
euvd EUVD-2026-41442

Description

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

References