Impact
The vulnerability is an incorrect authorization check in Azure Machine Learning. An attacker who does not have valid credentials could access data that should be protected, resulting in an information disclosure, impacting confidentiality. The flaw is a classic authorization-weakness scenario, classified as CWE-863.
Affected Systems
Microsoft Azure Machine Learning services are impacted. The vulnerability applies to all versions of the Azure Machine Learning product, as no specific affected version is listed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS is < 1%, suggesting a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. The likely attack vector is network; an unauthorized user could connect to the Azure Machine Learning endpoint and exploit the missing authorization checks to retrieve data.
OpenCVE Enrichment