CVE-2026-84003

Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability

Beschreibung

Die Umgehung der Authentifizierung durch Aufzeichnen und Wiedergeben in der Microsoft Authentication Library (MSAL) für Node.js ermöglicht es einem nicht autorisierten Angreifer, Spoofing über ein Netzwerk auszuführen.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.4
Quelle: nvd-v3
36.6 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-08 07:00 UTC
CWE-294

Weakness-Klassen (CWE)

  • CWE-294Base

    Authentication Bypass by Capture-replay

    A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. New CVE Received2026-09-08 18:21 UTC· secure@microsoft.com
    • Description: Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
    • CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
    • CWE: CWE-294
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/84xxx/CVE-2026-84003.json">CVE-2026-84003</a>

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Microsoft

    AzureArc SQL Server Extension

  • Microsoft

    AzureCycleCloud 8.9.2

  • Microsoft

    AzureHDInsight

  • Microsoft

    AzureSpring Cloud Azure

  • Microsoft

    EntraAuthentication Library (MSAL) for Node.js

IDCVE-2026-84003