nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery
Microsoft's Entra ID has a known security flaw that might let malicious actors to take over accounts in vulnerable software-as-a-service (SaaS) apps, according to new research.
In an examination of 104 SaaS services, identity security firm Semperis discovered that nine of them were susceptible to Entra ID cross-tenant nOAuth exploitation.
nOAuth is a flaw in the way SaaS apps use OpenID Connect (OIDC), an authentication layer that is built on top of OAuth to confirm a user's identity. Descope first revealed this flaw in June 2023.
In essence, the authentication implementation vulnerability enables a malicious actor to use the "Log in with Microsoft" function of the app to take over a victim's account by changing the mail attribute in the Entra ID account to that of the victim rea...

