As cited
Copy frozen at (site build).
cloud saas
OAuth, guest accounts, and weak MFA drive SaaS risk
Guest accounts created for temporary third-party access represent 69% of monitored SaaS accounts in 2025, with over 1.9 million more accounts than the previous year, often remaining active long after their intended use ends. Organizations face elevated risk from unmanaged guest accounts, OAuth misconfigurations, and weak multi-factor authentication (MFA) implementations across SaaS environments. These forgotten access paths create exploitable vectors for unauthorized access to corporate data.
Why it matters: SaaS administrators and security teams must audit and deactivate dormant guest accounts immediately, implement OAuth best practices, and enforce strong MFA to reduce the attack surface exposed to third-party compromises and insider threats.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
OAuth, guest accounts, and weak MFA drive SaaS risk
Guest accounts in SaaS environments pose significant security risks due to poor lifecycle management and insufficient controls. According to Kaseya's 2026 SaaS Security Report, guest accounts represent 69% of monitored SaaS accounts and outnumber licensed users, with over 1.9 million additional guest accounts added in 2025 compared to the prior year. Many remain active long after contractor, supplier, and partner access is no longer needed, creating exploitable pathways to corporate data.
Why it matters: Security teams need to audit and enforce guest account lifecycle policies immediately; unmanaged guest credentials are a direct attack vector that often bypasses standard access controls and compliance reviews.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
OAuth, guest accounts, and weak MFA drive SaaS risk
Guest accounts in SaaS environments pose significant security risks due to poor lifecycle management and insufficient controls. According to Kaseya's 2026 SaaS Security Report, guest accounts represent 69% of monitored SaaS accounts and outnumber licensed users, with over 1.9 million additional guest accounts added in 2025 compared to the prior year. Many remain active long after contractor, supplier, and partner access is no longer needed, creating exploitable pathways to corporate data.
Why it matters: Security teams need to audit and enforce guest account lifecycle policies immediately; unmanaged guest credentials are a direct attack vector that often bypasses standard access controls and compliance reviews.
- Source published
- First seen by Cybersecurity Tracker