Description
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in Azure CycleCloud permits an attacker who already has authorized access to read sensitive data over the network. The flaw is a classic authorization bypass that lets the attacker retrieve information that should be protected, potentially exposing configuration, credentials, or other confidential details. This weakness is mapped to CWE‑862, a missing access control vulnerability.

Affected Systems

Microsoft Azure CycleCloud version 8.9.2 is affected. No other versions are listed in the CNA data, so the impact is confined to the stated release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows that exploitation is unlikely in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate to the system, after which the missing authorization check can be leveraged remotely to pull information. Given the low EPSS probability, the risk is primarily confined to environments where privileged users are already present and any sensitive data may be exposed if access is misconfigured.

Generated by OpenCVE AI on August 12, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Azure CycleCloud to a version that contains the fix (if a patch is available beyond 8.9.2).
  • If an upgrade cannot be performed immediately, block or disable network access to the API endpoints that expose the offending functionality.
  • Restrict the permissions granted to authorized users so that only the minimum required operations are allowed, reducing the attack surface for potential disclosure.

Generated by OpenCVE AI on August 12, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Title Azure CycleCloud Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft azure Cyclecloud
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:azure_cyclecloud:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Cyclecloud
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Cyclecloud
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:17.303Z

Reserved: 2026-07-22T21:36:47.629Z

Link: CVE-2026-65806

cve-icon Vulnrichment

Updated: 2026-08-12T15:45:06.528Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:00.310

Modified: 2026-08-17T19:45:08.290

Link: CVE-2026-65806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T16:30:05Z

Weaknesses