← all CVEs

CVE-2026-59115

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Published 6 Aug 2026Updated 7 Aug 2026

Severity: CRITICAL

9.9

CVSS Base Score

Description

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

Affected products (1)

  • Microsoft Microsoft Entra Provisioning Service

Problem types

  • CWE-35: Path Traversal: '.../...//'

Get alerted the moment a CVE like this matches your stack.

Create a free account