50,000+ Azure AD Users Exposed via Unsecured API: BeVigil Uncovers Critical Flaw
ID: eea037cb-7064-5660-8f4e-6ead568f7446
STIX ID: report--eea037cb-7064-5660-8f4e-6ead568f7446
Feed Name: CloudSEK Blog
BeVigil discovered a critical misconfiguration where a client-side JavaScript file exposed an unauthenticated API endpoint that issued Microsoft Graph tokens with overly broad permissions (User.Read.All, AccessReview.Read.All), allowing retrieval of detailed Azure AD data for more than 50,000 users including executives; recommended mitigations include restricting public API access, revoking compromised tokens, enforcing least privilege, securing front-end code, and monitoring API usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
