logo

JSON Config File Leaks Azure ActiveDirectory Credentials

ID: d51ebed5-d642-53c3-b3c3-74ee3e5ec7dd

STIX ID: report--d51ebed5-d642-53c3-b3c3-74ee3e5ec7dd

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-09-02

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers found a publicly accessible ASP.NET Core appsettings.json file leaking Azure AD ClientId and ClientSecret, which would allow attackers to use the OAuth2 Client Credentials flow to obtain access tokens, query Microsoft Graph, enumerate users and permissions, and potentially escalate to tenant compromise; the report warns this is a common cloud misconfiguration and recommends removing secrets from configs, using secrets managers (Azure Key Vault/AWS Secrets Manager), rotating credentials, enforcing least privilege, and monitoring credential use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.