CVE Explorer
CVE-2026-45108
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability in the Device Authorization Grant (DAG) flow that allowed a user within the same Entra ID domain to obtain a local Unix session as another user by providing their own valid credentials. The vulnerability existed in the token_validate function, which validated domain aliases for legitimate multi-domain scenarios but fai
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"himmelblau","vendor":"himmelblau-idm","versions":[{"status":"affected","version":">= 2.0.0, < 2.3.11"},{"status":"affected","version":">= 3.0.0-alpha, < 3.1.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bd222c15bbd65ca1c287ff121b20828d0dec5ef3996e4d11ba465fbf0d9b6877 · sha256:7501eb737b85048b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bd222c15bbd65ca1c287ff121b20828d0dec5ef3996e4d11ba465fbf0d9b6877 · sha256:7501eb737b85048b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bd222c15bbd65ca1c287ff121b20828d0dec5ef3996e4d11ba465fbf0d9b6877 · sha256:7501eb737b85048b… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-pmxh-j4r6-88mv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/himmelblau-idm/himmelblau/security/advisories/GHSA-pmxh-j4r6-88mv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bd222c15bbd65ca1c287ff121b20828d0dec5ef3996e4d11ba465fbf0d9b6877 · sha256:7501eb737b85048b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.