CVE-2026-50481
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C
- EPSS probability
- 0.56%
- CWE
- CWE-471
- Published
- 2026-08-06
- Last modified
- 2026-09-09
Affected products
- Microsoft Azure Active Directory
Weakness type
Related vulnerabilities
- CVE-2026-54267 — Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
- CVE-2026-44798 — Nautobot: GitRepository.current_head field should not be writable through REST API
- CVE-2026-8492 — Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
- CVE-2025-33136 — IBM Aspera Faspex data modification
- CVE-2024-9876 — Application is vulnerable to Privilege escalation
- CVE-2024-55551 — An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject...
- CVE-2024-45672 — IBM Security Verify Bridge data manipulation
- CVE-2024-51462 — IBM QRadar WinCollect Agent data manipulation