CVE-2026-65673: Microsoft Entra Connect Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- EPSS Score
- 0.32% (percentile: 22.6%)
Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
Affected Products (1)
Azure
Security Updates (1)
Acknowledgments
Shira Hoffman
Revision History
- 2026-08-11: Information published.