🟠 High | Source: Microsoft Security Response Center
A path traversal-style vulnerability (using ‘../../../’ sequences) in Microsoft Entra’s Provisioning Service (SyncFabric) allows an already-authenticated attacker to escalate their privileges over the network. Because Entra Provisioning underpins identity synchronisation between on-premises directories and Azure AD, exploitation could grant an attacker broader control over user accounts and access policies. The requirement for prior authorisation reduces risk slightly, but the blast radius in hybrid identity environments is significant.
Security Architect’s Take: Audit which accounts and service principals have access to your Entra Provisioning Service and apply the principle of least privilege immediately. Monitor Microsoft’s MSRC page for a patch and prioritise deployment — in the meantime, restrict network access to SyncFabric endpoints and review provisioning agent logs for anomalous activity.
Original advisory: CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability