The Invisible Skeleton Key: How a Microsoft SSO Misconfiguration Can Hand Attackers Your Users' Accounts
When an application uses a mutable claim—like email or display name—instead of the immutable oid to identify users after OAuth login, a single pre-registered account can become a skeleton key to anyone's session. This is the story of how I first encountered this vulnerability, and what every developer implementing "Log in with Microsoft" needs to know.









