Security Advisory
CVE-2026-65673
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.