CVE-2026-50481Disclosure(microsoft / azure_active_directory)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_active_directory systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-471

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_active_directory

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-08-07); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
azure_active_directory

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-08-06: 1Mentions · 2026-08-07: 3Mentions · 2026-08-08: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-06: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-08: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-06: 1Technical Details · 2026-08-07: 3Technical Details · 2026-08-08: 1Technical Details · 2026-08-27: 108-0608-0708-0808-27
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-061
Disclosure1
2026-08-073
Disclosure2Patch1
2026-08-081
Patch1
2026-08-271
Patch1
Full discourse6 posts
  • National CERT/CC@CERT_UG
    Patch

    🔴 Patch Now | August 27, 2026 Bringing these CVEs to your attention: - Azure Active Directory (CVE-2026-50481, CVSS 9.9) - Windows AD Certificate Services (CVE-2026-62818, CVSS 8.8) - N-able N-central (CVE-2026-18577) #CyberSafeUG #CERTUGCC https://t.co/k8OQLM3Y0f

    Post summary

    The tweet alerts readers to three high‑severity CVEs and urges immediate patching, providing CVSS scores for context.

    0004092
    1.5K followersView on X
  • Sami Laiho@samilaiho
    Patch

    Azure Active Directory Elevation of Privilege Vulnerability URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9

    Post summary

    Microsoft has released an official fix for the critical Azure AD elevation‑of‑privilege vulnerability CVE‑2026‑50481, rated CVSS 9.9.

    01021873
    30.6K followersView on X
  • Steve Waterhouse@Water_Steve
    Patch

    Pour votre information // For your information Bon weekend ! Correctifs hors-cycle (#OoB) menaçant envers les les produits logiciels de @Microsoft et @Apple déployés En provenance de l'article de @SecurityWeek ci-bas mentionné: "Trois de ces vulnérabilités, CVE-2026-63508, CVE-2026-56162 et CVE-2026-65667, ont un niveau de gravité maximal de 10/10. Quatre autres vulnérabilités, CVE-2026-50515 (RCE dans #Azure Service Bus), CVE-2026-62830 (EoP dans #Azure SRE Agent), CVE-2026-59115 (EoP dans #Entra Provisioning Service) et CVE-2026-50481 (EoP dans #ActiveDirectory) ont un score CVSS de 9,9/10. Ces quatre vulnérabilités sont exploitables à distance. Des correctifs visant à remédier à cette faille de sécurité ont été intégrés dans #macOS #Tahoe 26.6.1, #macOS #Sequoia 15.7.9 et #macOS #Sonoma 14.8.9" 20260807 - #Microsoft, #Apple Release Fresh #SecurityUpdates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #infosec #cybersecurity #secinfo #cybersecurite #cyberwar #cyberwarfare #OPSEC @infosecsw #criticalinfrastructure #infrastructureessentielle #patchmanagement #gestioncorrectifs #DQP #ASAP

    Post summary

    The post announces out‑of‑cycle security patches for several high‑severity Microsoft and Apple CVEs, detailing affected macOS versions and providing CVSS scores and vulnerability types.

    01010161
    3.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-50481 ----- Traducción: CVE-2026-50481 Modificación de datos supuestame… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑50481, detailing that a modification of presumed immutable data in Azure AD permits privilege elevation, but it offers no PoC, exploit, or patch information.

    0000045
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-50481

    Post summary

    The post announces CVE-2026-50481, noting that modifying assumed‑immutable data in Azure Active Directory can lead to privilege escalation over a network; no PoC, exploit code, or mitigation details are provided.

    000001.1K
    57.9K followersView on X
  • Windows Forum@windowsforum
    Disclosure

    🚨 Microsoft disclosed an Entra elevation-of-privilege flaw with no patch, scope, or useful exposure details. Admins get a CVE number and the timeless advice: “good luck.” https://windowsforum.com/security-alerts.84/cve-2026-50481-entra-flaw-no-patch-or-scope-confirmed.441869/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CloudSecurity #CveVulnerabilities #IdentitySecurity #MicrosoftEntraId https://t.co/tHG9D8HBkH

    Post summary

    Microsoft disclosed an elevation‑of‑privilege flaw in Entra (CVE‑2026‑50481) with no patch or detailed exposure information provided.

    0000042
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_active_directory---

Explore more