Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
ID: f8932fed-7104-51cb-938d-f30ce67348ac
STIX ID: report--f8932fed-7104-51cb-938d-f30ce67348ac
Feed Name: Dark Reading
Azure Automation Elevation-of-Privilege (CVE-2025-29827) — A default-public configuration combined with two code-level bugs in Azure Automation could allow an attacker with access to their own Automation account to breach trust boundaries and assume another tenant's managed identity, potentially creating, modifying, or deleting resources and accessing stored credentials (CVSS 9.9). Researcher Shay Shavit reported the chain to MSRC, Microsoft changed the default setting and no exploitation has been observed, and organizations are advised to avoid exposing automation endpoints and to audit identity/token scope.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
