CVE-2026-31957

Source
https://cve.org/CVERecord?id=CVE-2026-31957
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31957.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-31957
Aliases
  • GHSA-q746-m2wv-qh4v
Published
2026-03-11T19:25:21.230Z
Modified
2026-04-01T23:10:16.237505Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Himmelblau unset domain configuration can allow any-tenant authentication at first login for remote deployments
Details

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelblau is deployed without a configured tenant domain in himmelblau.conf, authentication is not tenant-scoped. In this mode, Himmelblau can accept authentication attempts for arbitrary Entra ID domains by dynamically registering providers at runtime. This behavior is intended for initial/local bootstrap scenarios, but it can create risk in remote authentication environments. This vulnerability is fixed in 3.1.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31957.json",
    "cwe_ids": [
        "CWE-1188"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/himmelblau-idm/himmelblau

Affected ranges

Type
GIT
Repo
https://github.com/himmelblau-idm/himmelblau
Events

Affected versions

3.*
3.0.0
3.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31957.json"