This vulnerability meant that if an attacker had access to any user account in an organization, they could abuse actor tokens to gain full access to the Azure Active Directory (Entra ID) Graph API.
Not only did this allow access to sensitive data, but it also made it possible to impersonate other users by using their tokens. From there, attackers could escalate access all the way up to a Global Administrator, the highest-level role in Entra ID, giving them complete control over the environment.
For those who want the technical details, you can read Mollema’s full write-up here.


