Impact
Improper authorization in Azure Portal leads to the disclosure of sensitive information to an unauthorized attacker. The vulnerability allows a remote actor to retrieve data that should be restricted, compromising confidentiality for users of the portal. The weakness is classified as CWE-285, indicating an access control flaw that permits bypassing authorization checks.
Affected Systems
Microsoft Azure Portal is affected. No specific version details are provided, so all deployments of the portal are potentially vulnerable unless a specific update has been applied.
Risk and Exploitability
The CVSS score of 9.3 and an EPSS score of < 1% underscore a high‑severity risk with a measurable, though relatively low, probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated network request to a privileged endpoint, exploiting improper authorization rules to read data.
OpenCVE Enrichment