Impact
Azure SRE Agent Gateway - SignalR Hub suffers from improper authentication that allows an unauthorized attacker to read sensitive data over the network. The flaw falls under authentication failures, as denoted by CWE‑287 and improper request authentication, CWE‑863. A successful exploitation would expose confidential information, potentially compromising the integrity of the system and revealing internal state details.
Affected Systems
The vulnerability affects Microsoft Azure SRE Agent Gateway – SignalR Hub. Version details are not publicly disclosed in the CVE description, so apply the latest available release for all deployed instances.
Risk and Exploitability
The CVSS base score of 8.6 classifies the issue as High severity. However, the EPSS score of less than 1 % indicates a low likelihood of exploitation at present, and the vulnerability is not cataloged in the CISA KEV list. It is inferred that the attack vector is remote network access to the SignalR hub endpoints, requiring no special privileges or additional malware.
OpenCVE Enrichment