Himmelblau Authentication Vulnerability Allowing Cross-Tenant Access

Vulnerability

A vulnerability in Himmelblau, an interoperability suite for Microsoft Azure Entra ID and Intune, exists in versions 3.0.0 prior to 3.1.0. When deployed without a configured tenant domain, authentication is not restricted to specific tenants. This allows the application to accept authentication attempts from any Entra ID domain by dynamically registering providers at runtime. While this behavior is intended for initial bootstrap scenarios, it poses a risk in remote authentication environments by enabling unintended cross-tenant authentication.

Impact

Exploiting this vulnerability could lead to unauthorized cross-tenant authentication, allowing access beyond the operator's intended tenant boundary. This is particularly risky if the deployment uses Entra group-based role mapping, as an attacker could potentially gain privileged access on the host by satisfying group conditions within their controlled tenant. Additionally, if authentication occurs during the unscoped window after installation but before configuring a tenant domain, injected tenant details could persist and cause continued authentication scope beyond the intended boundary.

Remediation

To address this vulnerability, explicitly configure a tenant domain in the Himmelblau configuration file. After setting the domain, restart the Himmelblau daemons. For deployments that may have been compromised, audit local privileged group assignments and remove any unexpected entries. Monitor authentication logs for signs of unauthorized cross-tenant access.

Added: Mar 11, 2026, 8:37 PM
Updated: Mar 11, 2026, 8:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.