Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability
September 9th, 2026
Vulnerability Details
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the OAuth Device Code Grant endpoint. The issue results from the generation of error messages containing sensitive information. An attacker can leverage this vulnerability to disclose internal organizational information associated with arbitrary Entra ID tenants.
Additional Details
Fixed in version 2.1.24394.0
Disclosure Timeline
- 2026-03-31 - Vulnerability reported to vendor
- 2026-09-09 - Coordinated public release of advisory
- 2026-09-09 - Advisory Updated
Credit
Nelson William Gamazo Sanchez of TrendAI Research