{"cve":"CVE-2026-69836","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"[0,*]"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"product":"microsoft_entra_id","vendor":"microsoft"}],"created":"2026-08-21T00:45:07.128220+00:00","updated":"2026-08-21T20:00:13.907882+00:00","vendors":["microsoft","microsoft$PRODUCT$microsoft_entra_id"]},"epss":{"score":0.01532},"kev":{},"mitre":{"cpes":["cpe:2.3:a:microsoft:microsoft_entra_id:*:*:*:*:*:*:*:*"],"created":"2026-08-20T21:43:12.611000+00:00","description":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/69xxx/CVE-2026-69836.json","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836"],"title":"Microsoft Entra ID Remote Code Execution Vulnerability","updated":"2026-09-24T13:43:58.851000+00:00","vendors":["microsoft","microsoft$PRODUCT$microsoft_entra_id"],"weaknesses":["CWE-502"]},"nvd":{"cpes":["cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*"],"created":"2026-08-20T22:18:00.740000+00:00","description":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10.0,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-69836.json","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836"],"title":null,"updated":"2026-08-25T16:08:43.290000+00:00","vendors":["microsoft","microsoft$PRODUCT$entra_id"],"weaknesses":["CWE-502"]},"opencve":{"changes":[{"created":"2026-08-20T22:00:00+00:00","data":[{"details":{"new":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","old":null},"type":"description"},{"details":{"new":"Microsoft Entra ID Remote Code Execution Vulnerability","old":null},"type":"title"},{"details":["microsoft","microsoft$PRODUCT$microsoft_entra_id"],"type":"first_time"},{"details":{"added":["CWE-502"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:microsoft:microsoft_entra_id:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["microsoft","microsoft$PRODUCT$microsoft_entra_id"],"removed":[]},"type":"vendors"},{"details":{"added":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"18f0730c-b7c9-44a7-8b1c-52c1020867c0"},{"created":"2026-08-21T16:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"545cd2ed-c92e-4abf-9453-7849ab9cfc9a"},{"created":"2026-08-21T17:00:00+00:00","data":[{"details":{"added":{"kev":{"dateAdded":"2026-08-21T00:00:00+00:00","dueDate":"2026-08-24T00:00:00+00:00"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"d99f33d4-ef6c-4200-9ca3-95e5083a5c91"},{"created":"2026-08-21T18:45:00+00:00","data":[{"details":{"added":{},"removed":{"kev":{"dateAdded":"2026-08-21T00:00:00+00:00","dueDate":"2026-08-24T00:00:00+00:00"}},"updated":{}},"type":"metrics"}],"id":"3f7446bb-1b45-46e6-9595-d54f02282742"},{"created":"2026-08-25T16:15:00+00:00","data":[{"details":["microsoft$PRODUCT$entra_id"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["microsoft$PRODUCT$entra_id"],"removed":[]},"type":"vendors"}],"id":"af43733b-a462-4db9-a7e0-fd845ec9a3e8"},{"created":"2026-08-27T18:00:00+00:00","data":[{"details":{"added":["https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-69836"],"removed":[]},"type":"references"},{"details":{"added":{},"removed":{},"updated":{"ssvc":{"new":{"options":{"Automatable":"yes","Exploitation":"active","Technical Impact":"total"},"version":"2.0.3"},"old":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}}}},"type":"metrics"}],"id":"51ca01f0-66c1-4ae4-a94c-84e1806f700d"},{"created":"2026-08-29T17:30:00+00:00","data":[{"details":{"added":[],"removed":["https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-69836"]},"type":"references"},{"details":{"added":{},"removed":{},"updated":{"ssvc":{"new":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"old":{"options":{"Automatable":"yes","Exploitation":"active","Technical Impact":"total"},"version":"2.0.3"}}}},"type":"metrics"}],"id":"2e945041-c9ba-428d-9d00-10edd1b95a90"}],"cpes":{"data":["cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:microsoft_entra_id:*:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-20T21:43:12.611000+00:00","provider":"mitre"},"description":{"data":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.01532},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836"],"providers":["mitre","nvd"]},"title":{"data":"Microsoft Entra ID Remote Code Execution Vulnerability","provider":"mitre"},"updated":{"data":"2026-08-29T16:21:04.208000+00:00","provider":"mitre"},"vendors":{"data":["microsoft","microsoft$PRODUCT$entra_id","microsoft$PRODUCT$microsoft_entra_id"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-502"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-08-20T21:43:12.611000+00:00","description":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Microsoft Entra ID Remote Code Execution Vulnerability","updated":"2026-08-21T15:33:42.806000+00:00","vendors":[],"vulnrichment_repo_path":"2026/69xxx/CVE-2026-69836.json","weaknesses":[]}}