CVE-2026-31957 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tena…
Critical CVSS: 10.0

CVE-2026-31957

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime. This behavior is intended for initial/local bootstrap scenarios, but it can create risk in remote authentication environments. This vulnerability is fixed in 3.1.0.
Vendor
Himmelblau-idm
Product
Himmelblau
CWE
CWE-1188
Yayın Tarihi
2026-03-11 20:16:16
Güncelleme
2026-03-16 19:39:37
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar