logo

Microsoft rejects critical Azure vulnerability report, no CVE issued

ID: 1d99ddb0-9d0d-56ed-9160-1cfa0bc7edfb

STIX ID: report--1d99ddb0-9d0d-56ed-9160-1cfa0bc7edfb

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Ax Sharma

...
...

A security researcher reported a Confused Deputy privilege-escalation flaw in Azure Backup for AKS that allowed an attacker with only Backup Contributor role on a vault to trigger Trusted Access and gain Kubernetes cluster-admin privileges, enabling secret exfiltration or deployment of malicious workloads. CERT/CC validated the issue and assigned a tracking identifier, but Microsoft disputed the finding, recommended against CVE issuance, and—according to the researcher—appears to have silently changed behavior and added permission checks without issuing a public advisory, leaving defenders uncertain about exposure windows and remediation timelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.