Impact
This vulnerability stems from missing authorization controls (CWE‑862) in Azure CycleCloud that allow an attacker with legitimate credentials to gain higher privileges across the network. The flaw enables a user who is already authenticated to perform actions normally restricted to more privileged roles, potentially accessing or altering sensitive resources. The impact is a classic privilege escalation that can compromise confidentiality, integrity, or availability of cloud-based resources.
Affected Systems
Microsoft Azure CycleCloud version 8.9.1 is affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a network‑connected attacker who can authenticate to the Azure CycleCloud instance and then exploit the lack of proper authorization checks to elevate privileges.
OpenCVE Enrichment