Impact
Microsoft Azure CycleCloud contains a missing authentication check for a critical function, allowing an attacker who is already authenticated to the platform to elevate privileges within the system. This is a CWE‑306 vulnerability that can compromise the integrity of the affected environment, giving attackers greater control than intended.
Affected Systems
The affected system is Microsoft Azure CycleCloud version 8.9.1.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level, while an EPSS score of less than 1% suggests that exploitation attempts are currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw involves absent authentication for a network‑exposed function, the likely attack vector is over a network connection to Azure CycleCloud, requiring the attacker to have some level of authorized access to the platform but not the proper authentication for the privileged function. If exploited, the attacker could gain elevated privileges, potentially accessing or modifying critical system data.
OpenCVE Enrichment