Microsoft Azure API Management Flaw Enables Cross-Tenant Account Creation, Bypassing Admin Restrictions
ID: 3b2b470e-577d-5e11-87c6-7d3d72cc1ad8
STIX ID: report--3b2b470e-577d-5e11-87c6-7d3d72cc1ad8
Feed Name: cybersecurityNews.com
**Azure APIM Developer Portal Host-header signup bypass:** A design flaw allows attackers to create accounts across tenant instances by manipulating the Host header against the signup API when Basic Authentication is enabled, even if signup is visually disabled in the portal. The issue (CVSS 6.5) can lead to cross-tenant account creation, administrative access bypass, and potential exposure of API docs and subscription keys; Microsoft classified the behavior as "by design" and has not patched it, and the researcher published verification scripts and a Nuclei template. Recommended mitigations include removing the Basic Authentication identity provider, switching to Azure AD authentication, auditing portal accounts, and monitoring signup/API activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
