CVE-2026-31957Disclosure(himmelblau-idm / himmelblau)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch himmelblau-idm himmelblau systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime. This behavior is intended for initial/local bootstrap scenarios, but it can create risk in remote authentication environments. This vulnerability is fixed in 3.1.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • himmelblau

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-11); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Products
himmelblau

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-11: 4Mentions · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-11: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-12: 103-1103-12
Signal classification1 categories
Disclosure
5100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-114
Disclosure4
2026-03-121
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-31957 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant dom… https://www.cve.org/CVERecord?id=CVE-2026-31957

    Post summary

    The text announces CVE-2026-31957 affecting Himmelblau 3.0.0 to before 3.1.0, highlighting a missing tenant domain configuration issue and linking to the CVE record for details.

    00010194
    56.6K followersView on X
  • 齋藤氏@Saito0409
    Disclosure

    ヒンメルブラウは青空? EntraとIntuneに関連するシステムっぽいが、、、 ■Himmelblau脆弱性 https://nvd.nist.gov/vuln/detail/CVE-2026-31957 ■Unset domain configuration can allow any-tenant authentication at first login for remote deployments https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-q746-m2wv-qh4v

    Post summary

    The post introduces CVE‑2026‑31957, noting an authentication bypass due to unset domain configuration, but offers no PoC, exploit code, active exploitation evidence, or patch details.

    0000043
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31957 Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant dom… https://www.cve.org/CVERecord?id=CVE-2026-31957 ----- Traducción: CVE-2026-31957 Him… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-31957 for the Himmelblau interoperability suite on Azure Entra ID/Intune, noting affected versions and a missing tenant domain configuration, without any PoC, exploit, or patch details.

    0000026
    57 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-31957: CRITICAL] Attention to users of Himmelblau on Microsoft Azure Entra ID and Intune! A critical vulnerability from version 3.0.0 to 3.1.0 has been fixed to enhance tenant-scoped authentication.#cve,CVE-2026-31957,#cybersecurity https://cvefind.com/CVE-2026-31957

    Post summary

    The message alerts that CVE-2026-31957, a critical vulnerability affecting Himmelblau on Azure Entra ID and Intune, has been fixed in version 3.1.0, with no proof‑of‑concept or exploitation details provided.

    0000046
    600 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31957: Himmelbla... Misconfigured Himmelblau accepts auth from ANY Azure tenant—perfect for initial access via tenant confusion attacks. #AzureAD #TenantTakeover. https://zerodaysignal.com/vulnerability/CVE-2026-31957 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE‑2026‑31957 is highlighted as a misconfigured Himmelblau that allows authentication from any Azure tenant, enabling tenant confusion attacks. The post announces the vulnerability but does not include exploit code or remediation details.

    0000047
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphimmelblau-idmhimmelblau---

Explore more