Description
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from missing authorization controls (CWE‑862) in Azure CycleCloud that allow an attacker with legitimate credentials to gain higher privileges across the network. The flaw enables a user who is already authenticated to perform actions normally restricted to more privileged roles, potentially accessing or altering sensitive resources. The impact is a classic privilege escalation that can compromise confidentiality, integrity, or availability of cloud-based resources.

Affected Systems

Microsoft Azure CycleCloud version 8.9.1 is affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a network‑connected attacker who can authenticate to the Azure CycleCloud instance and then exploit the lack of proper authorization checks to elevate privileges.

Generated by OpenCVE AI on August 1, 2026 at 09:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official patch or upgrade to a non‑vulnerable Azure CycleCloud version
  • Restrict network access for privileged accounts to trusted hosts and reduce potential lateral movement
  • Enforce stricter role‑based access controls and audit privileged account activity

Generated by OpenCVE AI on August 1, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Title Azure CycleCloud Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Cyclecloud
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:azure_cyclecloud:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Cyclecloud
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Azure Cyclecloud
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:02.477Z

Reserved: 2026-06-29T21:59:30.870Z

Link: CVE-2026-58279

cve-icon Vulnrichment

Updated: 2026-07-14T17:36:21.366Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses