CVE-2026-84003

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:azure\/msal-node:*:*:*:*:*:node.js:*:*

History

16 Sep 2026, 14:06

Type Values Removed Values Added
First Time Microsoft
Microsoft azure\/msal-node
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84003 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84003 - Vendor Advisory
CPE cpe:2.3:a:microsoft:azure\/msal-node:*:*:*:*:*:node.js:*:*

Information

Published : 2026-09-08 18:21

Updated : 2026-09-16 14:06


NVD link : CVE-2026-84003

Mitre link : CVE-2026-84003

CVE.ORG link : CVE-2026-84003


JSON object : View

Products Affected

microsoft

  • azure\/msal-node
CWE
CWE-294

Authentication Bypass by Capture-replay