Description
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Published: 2026-07-24
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authorization in Azure Portal leads to the disclosure of sensitive information to an unauthorized attacker. The vulnerability allows a remote actor to retrieve data that should be restricted, compromising confidentiality for users of the portal. The weakness is classified as CWE-285, indicating an access control flaw that permits bypassing authorization checks.

Affected Systems

Microsoft Azure Portal is affected. No specific version details are provided, so all deployments of the portal are potentially vulnerable unless a specific update has been applied.

Risk and Exploitability

The CVSS score of 9.3 and an EPSS score of < 1% underscore a high‑severity risk with a measurable, though relatively low, probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated network request to a privileged endpoint, exploiting improper authorization rules to read data.

Generated by OpenCVE AI on August 3, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Azure Portal security update published by Microsoft via the MSRC link
  • Reconfigure Azure Active Directory permissions to ensure that only authorized roles can access sensitive portal functions and remove any overly permissive roles
  • Implement continuous monitoring of API calls and audit logs to detect and respond to unauthorized data disclosure attempts

Generated by OpenCVE AI on August 3, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Title Azure Portal Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft azure Portal
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:azure_portal:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Portal
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:34.538Z

Reserved: 2026-07-14T21:10:38.083Z

Link: CVE-2026-62835

cve-icon Vulnrichment

Updated: 2026-07-25T01:01:13.847Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T20:18:19.410

Modified: 2026-07-29T15:01:25.857

Link: CVE-2026-62835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T19:45:07Z

Weaknesses