Ongoing Risk of nOAuth Vulnerability in Microsoft Entra SaaS Apps

TL;DR
Research reveals that 9% of Microsoft Entra SaaS apps remain vulnerable to nOAuth abuse, a security flaw in OpenID Connect implementation that can lead to account hijacking and data breaches, despite being disclosed two years ago. The vulnerability exploits cross-tenant access and unverified emails, with Microsoft urging developers to properly implement authentication measures to prevent exploitation.
Topics:technologysaas-security#account-takeover#microsoft-entra-id#noauth#openid-connect#saas-security#saas-vulnerabilities
- nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery The Hacker News
- nOAuth Lives On in Cloud App Logins Using Entra ID BankInfoSecurity
- Microsoft nOAuth Flaw Still Exposes SaaS Apps Two Years After Discovery Infosecurity Magazine
- Thousands of SaaS Apps Could Still Be Susceptible to nOAuth SecurityWeek
- Semperis Research Uncovers Ongoing Risk from nOAuth Vulnerability in Microsoft Entra ID, Affecting Enterprise SaaS Applications PR Newswire
Want the full story? Read the original reporting
Read on The Hacker News