SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84003

HIGH · CVSS 7.4 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Microsoft Authentication Library (MSAL) for Node.js is vulnerable to an authentication bypass due to a capture-replay attack, enabling unauthorized attackers to spoof user identities over the network. This high-severity flaw poses significant risks to applications relying on MSAL for secure authentication. Organizations using this library should prioritize patching to mitigate potential exploitation and protect sensitive user data.

CVE
CVE-2026-84003
Severity
HIGH
CVSS
7.4
EPSS
0.43%
Microsoft

Original NVD Description

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)