Description
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-20
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the cryptographic signature verification routine of Azure Data Factory, permitting an attacker without proper authorization to elevate their privileges across the network. This results in the attacker gaining higher levels of access than intended, potentially compromising the confidentiality, integrity, or availability of data and services governed by the affected instance. The weakness is identified as CWE-347, indicating improper handling of cryptographic signatures.

Affected Systems

Microsoft Azure Data Factory is the affected product; no specific versions are listed.

Risk and Exploitability

The CVSS score of 9.3 reflects a critical severity, and although the EPSS score is not available, the absence of the vulnerability from the CISA KEV catalog suggests that widespread exploitation has not yet been observed. Attacks would likely occur over the network by sending malicious requests that the service mistakenly accepts due to the signature check flaw. No additional prerequisites or environmental conditions are indicated in the description. The potential impact and high score recommend vigilance.

Generated by OpenCVE AI on August 21, 2026 at 00:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Microsoft Azure security advisory page for any updates or patches addressing CVE-2026-62834 and apply them when available.
  • Review and tighten role-based access controls in Azure Data Factory to ensure that service principals and users possess the minimal permissions required for their functions.
  • Disable or revoke any unused or overly permissive API endpoints and monitor for unusual activity that could indicate privilege escalation attempts.

Generated by OpenCVE AI on August 21, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_data_factory:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
Title Azure Data Factory Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Data Factory
Weaknesses CWE-347
CPEs cpe:2.3:a:microsoft:azure_data_factory:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Data Factory
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Data Factory
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:34:34.865Z

Reserved: 2026-07-14T21:10:38.083Z

Link: CVE-2026-62834

cve-icon Vulnrichment

Updated: 2026-08-21T13:34:40.969Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:43.070

Modified: 2026-08-24T17:44:30.080

Link: CVE-2026-62834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:00:04Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature