Critical Azure Entra ID Flaw Highlights Microsoft IAM Issues
Critical Azure Entra ID Flaw Highlights Microsoft IAM Issues Summary A high-severity elevation-of-privilege vulnerability (CVE-2025-55241) in Microsoft’s Azure AD Graph API could have allowed attackers to impersonate users — including global admins — across tenants. Discovered by Dirk-jan Mollema, the issue hinges on an authentication failure combined with undocumented, unsigned “Actor” tokens that bypass access […]