VDB

GCVE-110-CLOUD-2023-0058

GCVE-110-CLOUD-2023-0058
Advisory Published
Vulnetix · Advisory published January 18, 2023
A vulnerability in Azure Active Directory allowed users to retain access to SAML applications after their assignment was removed. Attackers could exploit this to establish persistence and elevate privileges on targeted SAML applications. The flaw was triggered by chaining sign-in with additional application and specific parameters in the token request, bypassing user assignment verification.

Affected Products

VendorProductVersionsPlatforms
AzureActive Directory
AzureAzure Active Directory
AzureCloud Services

References

advisory

Browse GCVE Records

73,866 records in the GCVE database · Updated July 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›