CVE Tools

CVE-2026-59115

Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

Published: Aug 6, 2026Updated: Aug 7, 2026 Sources: CVE List NVDCWE-35

Description

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

In plain language

AI Act now

CVE-2026-59115 is a serious privilege-escalation flaw in Microsoft Entra Provisioning Service that could let an attacker with authorized access gain much higher control; if you run this service, you should treat it as urgent and install Microsoft’s fix.

Executive summary

Microsoft Entra Provisioning Service (SyncFabric) has an elevation of privilege weakness (CWE-35) that can be triggered by an authorized attacker via an input that includes a ‘.../...//’ path pattern, allowing them to elevate privileges over the network.

If affected, business impact
Full service takeover riskCompromise of connected identitiesWider access to corporate appsDisruption of provisioning operations

What to do now

  1. Check whether your organization uses Microsoft Entra Provisioning Service (including the SyncFabric component) for user/app provisioning.
  2. If you do, open the Microsoft MSRC update guide for CVE-2026-59115 and confirm which remediation/updates apply to your deployed setup.
  3. Install the fix from Microsoft immediately, following the MSRC guidance for your environment.
  4. After updating, verify the provisioning service is operating normally and review related service logs for any unusual activity around authentication/provisioning operations.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

Official Patch Available

References

7

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-59115 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store