CVE-2026-57100
Critical · CVSS 9.9Microsoft Entra Provisioning Service (SyncFabric) — Server-Side Request Forgery (SSRF) leading to Privilege Escalation
- CVSS
- 9.9
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-918
Description
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Search profile — drives PoC discovery
Symbols SyncFabricEntra Provisioning ServiceSSRFprivilege escalationCWE-918
Keywords CVE-2026-57100Microsoft EntraSyncFabricSSRFprovisioning serviceprivilege escalationserver-side request forgeryEntra ProvisioningPoCproof of concept
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0unknownperson89800/Creative-CTF-TryHackme-Walkthrow needs reviewgh_search
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-09T00:00:39.000Z · profiled 2026-07-09T00:30:39.000Z