CVE-2026-59115
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Description
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-59115 is a serious privilege-escalation flaw in Microsoft Entra Provisioning Service that could let an attacker with authorized access gain much higher control; if you run this service, you should treat it as urgent and install Microsoft’s fix.
Microsoft Entra Provisioning Service (SyncFabric) has an elevation of privilege weakness (CWE-35) that can be triggered by an authorized attacker via an input that includes a ‘.../...//’ path pattern, allowing them to elevate privileges over the network.
What to do now
- Check whether your organization uses Microsoft Entra Provisioning Service (including the SyncFabric component) for user/app provisioning.
- If you do, open the Microsoft MSRC update guide for CVE-2026-59115 and confirm which remediation/updates apply to your deployed setup.
- Install the fix from Microsoft immediately, following the MSRC guidance for your environment.
- After updating, verify the provisioning service is operating normally and review related service logs for any unusual activity around authentication/provisioning operations.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft's Patch Tuesday Deluge Continues With August Updatesen·Dark Reading· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsen·The Hacker News· Exploited Mythos 5 UNC6671
- Microsoft, Apple Release Fresh Security Updatesen-us·SecurityWeek· Patch Active Directory patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-59115 and every CVE in our database. Create a free account — no credit card required.
Create Free Account