Description
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Azure CycleCloud contains a missing authentication check for a critical function, allowing an attacker who is already authenticated to the platform to elevate privileges within the system. This is a CWE‑306 vulnerability that can compromise the integrity of the affected environment, giving attackers greater control than intended.

Affected Systems

The affected system is Microsoft Azure CycleCloud version 8.9.1.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity level, while an EPSS score of less than 1% suggests that exploitation attempts are currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw involves absent authentication for a network‑exposed function, the likely attack vector is over a network connection to Azure CycleCloud, requiring the attacker to have some level of authorized access to the platform but not the proper authentication for the privileged function. If exploited, the attacker could gain elevated privileges, potentially accessing or modifying critical system data.

Generated by OpenCVE AI on July 31, 2026 at 09:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Azure CycleCloud update that includes authentication controls for the critical function.
  • Limit network access to Azure CycleCloud services to trusted IP addresses or VPN endpoints to reduce exposure.
  • Ensure the critical function enforces proper authentication and authorization checks before executing privileged actions.

Generated by OpenCVE AI on July 31, 2026 at 09:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Title Azure CycleCloud Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Cyclecloud
Weaknesses CWE-306
CPEs cpe:2.3:a:microsoft:azure_cyclecloud:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Cyclecloud
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Cyclecloud
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:37.199Z

Reserved: 2026-06-26T17:45:44.853Z

Link: CVE-2026-57969

cve-icon Vulnrichment

Updated: 2026-07-15T10:57:32.907Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function