logo

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

ID: f8932fed-7104-51cb-938d-f30ce67348ac

STIX ID: report--f8932fed-7104-51cb-938d-f30ce67348ac

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Jeffrey Schwartz

...
...

Azure Automation Elevation-of-Privilege (CVE-2025-29827) — A default-public configuration combined with two code-level bugs in Azure Automation could allow an attacker with access to their own Automation account to breach trust boundaries and assume another tenant's managed identity, potentially creating, modifying, or deleting resources and accessing stored credentials (CVSS 9.9). Researcher Shay Shavit reported the chain to MSRC, Microsoft changed the default setting and no exploitation has been observed, and organizations are advised to avoid exposing automation endpoints and to audit identity/token scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.