logo

Azure Identity Token Flaw Exposes Windows Admin Center to Tenant-Wide Breaches

ID: dd29e9e4-5536-5acd-87eb-3bc894f2d8c3

STIX ID: report--dd29e9e4-5536-5acd-87eb-3bc894f2d8c3

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-16

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** Cymulate Research Labs disclosed CVE-2026-20965, a high-severity authentication bypass in Microsoft Windows Admin Center’s Azure SSO that fails to bind Proof-of-Possession (PoP) tokens to access tokens, enabling an attacker with local administrator access on one machine to escalate to tenant-wide compromise of WAC-managed systems; Microsoft released a patch and organizations must upgrade to Windows Admin Center Azure Extension 0.70.00 to mitigate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.