Impact
Missing authorization in Azure CycleCloud permits an attacker who already has authorized access to read sensitive data over the network. The flaw is a classic authorization bypass that lets the attacker retrieve information that should be protected, potentially exposing configuration, credentials, or other confidential details. This weakness is mapped to CWE‑862, a missing access control vulnerability.
Affected Systems
Microsoft Azure CycleCloud version 8.9.2 is affected. No other versions are listed in the CNA data, so the impact is confined to the stated release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows that exploitation is unlikely in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate to the system, after which the missing authorization check can be leveraged remotely to pull information. Given the low EPSS probability, the risk is primarily confined to environments where privileged users are already present and any sensitive data may be exposed if access is misconfigured.
OpenCVE Enrichment