nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

Microsoft’s Entra ID has a known security flaw that might let malicious actors to take over accounts in vulnerable software-as-a-service (SaaS) apps, according to new research.

In an examination of 104 SaaS services, identity security firm Semperis discovered that nine of them were susceptible to Entra ID cross-tenant nOAuth exploitation.

nOAuth is a flaw in the way SaaS apps use OpenID Connect (OIDC), an authentication layer that is built on top of OAuth to confirm a user’s identity. Descope first revealed this flaw in June 2023.

In essence, the authentication implementation vulnerability enables a malicious actor to use the “Log in with Microsoft” function of the app to take over a victim’s account by changing the mail attribute in the Entra ID account to that of the victim read more about nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *