Ongoing Risk of nOAuth Vulnerability in Microsoft Entra SaaS Apps

1 min read
Source: The Hacker News
Ongoing Risk of nOAuth Vulnerability in Microsoft Entra SaaS Apps
Photo: The Hacker News
TL;DR

Research reveals that 9% of Microsoft Entra SaaS apps remain vulnerable to nOAuth abuse, a security flaw in OpenID Connect implementation that can lead to account hijacking and data breaches, despite being disclosed two years ago. The vulnerability exploits cross-tenant access and unverified emails, with Microsoft urging developers to properly implement authentication measures to prevent exploitation.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News