← Vulnerability feed

Vulnerability record · CVE-2021-42306 · published 24 November 2021

CVE-2021-42306: Microsoft azure active directory insufficiently protected credentials vulnerability

Microsoft · Azure Active Directory

An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application. Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information. For more details on this issue, please refer to the MSRC Blog Entry.

8.1 CVSS 3.1 High EPSS 3.3% · top 12.1% CWE-522 · Insufficiently protected credentials
8.1CVSS 3.1 base score, v2 4.0
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
19 Aug 2026Last modified by NVD

Description

An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application. Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information. For more details on this issue, please refer to the MSRC Blog Entry.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-42306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-45480Microsoft azure active directory improper authentication vulnerabilityImproper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.EPSS 0.90%9.9CVE-2026-50481Microsoft azure active directory vulnerabilityModification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.EPSS 0.82%8.8CVE-2025-29827Microsoft azure automation improper authorization vulnerabilityImproper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.EPSS 1.6%7.8CVE-2024-21330Microsoft azure automation heap-based buffer overflow vulnerabilityOpen Management Infrastructure (OMI) Elevation of Privilege VulnerabilityEPSS 0.99%7.5CVE-2026-50652Microsoft .net framework deserialization of untrusted data vulnerabilityDeserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.EPSS 1.7%7.5CVE-2026-50653Microsoft .net framework uncontrolled resource consumption vulnerabilityLoop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.EPSS 1.2%6.8CVE-2024-21381Microsoft azure active directory cross-site request forgery vulnerabilityMicrosoft Azure Active Directory B2C Spoofing VulnerabilityEPSS 0.42%6.4CVE-2024-26193Microsoft azure migrate improper authorization vulnerabilityAzure Migrate Remote Code Execution VulnerabilityEPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2021-42306), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.