Description
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Microsoft Entra ID SSO Login allows Privilege Escalation.This issue affects Microsoft Entra ID SSO Login: from 0.0.0 before 1.0.4.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.0.0 (semver) before 1.0.4
Credits
Ashish Verma (ashish.verma85)
Dheeraj Jhamtani (dheeraj jhamtani)
Marcelo Vani (marcelovani)
Jaseer Kinangattil (jaseerkinangattil)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2026-005