CVE-2026-62916CWE-288

CVE-2026-62916

Critical · published September 4, 2026

CVSS v3.1
9.1
EPSS
1%
Percentile
45.6
In the wild
Unconfirmed
What it is

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00582 · 45.6th percentile
Weakness
CWE-288 · Authentication Bypass Using an Alternate Path or Channel
Published
2026-09-04T03:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:43Z
    EPSS moved — → 1%
    epss
  • 03 SEP 22:59Z
    Microsoft Entra ID Elevation of Privilege Vulnerability
    cvelistv5