logo

50,000+ Azure AD Users Exposed via Unsecured API: BeVigil Uncovers Critical Flaw

ID: eea037cb-7064-5660-8f4e-6ead568f7446

STIX ID: report--eea037cb-7064-5660-8f4e-6ead568f7446

Feed Name: CloudSEK Blog

Threat Score
80/100

Date Published: 2025-05-30

Date Updated: 2026-04-27

...
...

BeVigil discovered a critical misconfiguration where a client-side JavaScript file exposed an unauthenticated API endpoint that issued Microsoft Graph tokens with overly broad permissions (User.Read.All, AccessReview.Read.All), allowing retrieval of detailed Azure AD data for more than 50,000 users including executives; recommended mitigations include restricting public API access, revoking compromised tokens, enforcing least privilege, securing front-end code, and monitoring API usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.