Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

September 9th, 2026

Vulnerability Details

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the OAuth Device Code Grant endpoint. The issue results from the generation of error messages containing sensitive information. An attacker can leverage this vulnerability to disclose internal organizational information associated with arbitrary Entra ID tenants.

Additional Details

Fixed in version 2.1.24394.0


Disclosure Timeline

  • 2026-03-31 - Vulnerability reported to vendor
  • 2026-09-09 - Coordinated public release of advisory
  • 2026-09-09 - Advisory Updated

Credit

Nelson William Gamazo Sanchez of TrendAI Research

Back to Advisories