nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

nOAuth Vulnerability Still Affects 9% of Microsoft Entra SaaS Apps Two Years After Discovery

Recent research highlights ongoing security risks related to Microsoft’s Entra ID, specifically vulnerabilities allowing account takeovers through nOAuth abuse in SaaS applications. Microsoft and security experts recommend strict implementation of authentication standards to prevent exploitation and safeguard organizational data. #EntraID #nOAuth #MicrosoftEntra #SaaSApplications

Keypoints

  • Security weaknesses in Microsoft’s Entra ID can enable malicious account hijacking through nOAuth abuse.
  • Vulnerable SaaS applications allow attackers to exploit cross-tenant access and impersonate users.
  • Proper implementation of OpenID Connect standards is essential to prevent authentication flaws.
  • Microsoft has reiterated guidelines to developers and warned of possible app removal from the Entra App Gallery.
  • Misconfigured Kubernetes containers can also expose AWS credentials, increasing the risk of privilege escalation and data breaches.

Read More: https://thehackernews.com/2025/06/noauth-vulnerability-still-affects-9-of.html