Description
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in the Azure DNS service that lets an unauthorized user elevate privileges within the network. This flaw maps to CWE-862 and, if exploited, could allow the attacker to gain higher level access to DNS records or management functions, potentially compromising the confidentiality, integrity, and availability of DNS data for the affected Azure subscription.

Affected Systems

Microsoft Azure DNS is affected. Specific affected versions were not disclosed, so any deployment using Azure DNS without the latest updates is potentially at risk.

Risk and Exploitability

The CVSS score of 10.0 signals a critical severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA KEV, suggesting that no widespread, publicly known exploitation campaigns have been documented yet. The likely attack vector is over the public network via Azure DNS APIs, where an attacker with no prior authorization can interact with the service and trigger the privilege escalation if the missing check is not addressed.

Generated by OpenCVE AI on August 3, 2026 at 20:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest updates or patches released by Microsoft that close the missing authorization flaw in Azure DNS
  • Restrict access to Azure DNS management endpoints by configuring Network Security Groups or firewall rules to allow only authorized IP ranges
  • Enforce strict role‑based access controls on all Azure DNS resources to mitigate the impact if the flaw is somehow bypassed

Generated by OpenCVE AI on August 3, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Title Azure DNS Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Dns
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:azure_dns:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Dns
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Dns
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:34.093Z

Reserved: 2026-06-29T21:59:30.869Z

Link: CVE-2026-58275

cve-icon Vulnrichment

Updated: 2026-07-24T11:08:33.861Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:17:40.863

Modified: 2026-08-07T18:08:02.930

Link: CVE-2026-58275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses