logo

'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

ID: e1ea3f2b-cb6e-55bf-af79-1690aea3d872

STIX ID: report--e1ea3f2b-cb6e-55bf-af79-1690aea3d872

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Rob Wright

...
...

The report details two significant "confused deputy" vulnerabilities in major cloud platforms: an Azure AKS backup Trusted Access flaw that can escalate Backup Contributor privileges to cluster-admin, and a GCP Config Connector IAM bypass that can let a Kubernetes user obtain Organization Owner rights. The researcher disclosed both to Microsoft and Google; Microsoft appears to have silently patched its issue, while Google declined a bounty and did not classify the Config Connector behavior as a vulnerability despite the tool's wide deployment, including in FedRAMP-authorized environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.