nOAuth Abuse Alert: Full Account Takeover of Entra Cross-Tenant SaaS Applications
semperis.com | vulnerability | #account-takeover | #entra-id | #vulnerability | #saas-security | #noauth | #cross-tenant
Summary
Semperis found 9 of 104 tested SaaS apps vulnerable to nOAuth abuse: with an Entra tenant and a victim's email, an attacker can take over accounts. The flaw is severe and hard to defend against.
- Published
- Collected
Skip to content