logo

Microsoft Azure API Management Flaw Enables Cross-Tenant Account Creation, Bypassing Admin Restrictions

ID: 3b2b470e-577d-5e11-87c6-7d3d72cc1ad8

STIX ID: report--3b2b470e-577d-5e11-87c6-7d3d72cc1ad8

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Azure APIM Developer Portal Host-header signup bypass:** A design flaw allows attackers to create accounts across tenant instances by manipulating the Host header against the signup API when Basic Authentication is enabled, even if signup is visually disabled in the portal. The issue (CVSS 6.5) can lead to cross-tenant account creation, administrative access bypass, and potential exposure of API docs and subscription keys; Microsoft classified the behavior as "by design" and has not patched it, and the researcher published verification scripts and a Nuclei template. Recommended mitigations include removing the Basic Authentication identity provider, switching to Azure AD authentication, auditing portal accounts, and monitoring signup/API activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.