Description
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authentication in Microsoft Azure Key Vault permits an attacker without valid credentials to acquire elevated privileges over the network, thereby enabling unauthorized access to stored keys, secrets, and certificates. The flaw is a classic authentication bypass (CWE‑287), meaning the attacker can assume roles or privileges beyond those intended by the administrator, potentially compromising sensitive data and operations.

Affected Systems

Microsoft Azure Key Vault is affected. No specific version range is listed, so all deployed instances may be vulnerable until a patch is applied or the access model is changed.

Risk and Exploitability

The CVSS score of 10.0 reflects a high‑risk vulnerability with full privileges. The EPSS score is below 1%, indicating a very low current exploitation probability, and the vulnerability is not catalogued in CISA’s KEV. Based on the description, it is inferred that an attacker could send crafted authentication requests to bypass the service’s identity validation, which suggests the attack could be performed remotely over the network if the service is exposed.

Generated by OpenCVE AI on August 3, 2026 at 20:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Azure Key Vault security update or patch released by Microsoft—consult the MSRC advisory link for the latest fix.
  • Review and tighten Azure‑based access controls, ensuring that RBAC and Key Vault access policies grant only the minimum permissions required for each user or service principal.
  • Enable additional protection layers such as Azure Defender for Key Vault and implement network controls (e.g., private endpoints, network security groups) to limit exposure of the Key Vault endpoint to trusted traffic.

Generated by OpenCVE AI on August 3, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Title Azure Key Vault Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Key Vault
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:azure_key_vault:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Key Vault
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Key Vault
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:32.888Z

Reserved: 2026-07-14T21:10:38.082Z

Link: CVE-2026-62825

cve-icon Vulnrichment

Updated: 2026-07-24T12:21:57.435Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:17:47.030

Modified: 2026-08-07T19:30:11.300

Link: CVE-2026-62825

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses