Impact
The CVE arises from a missing authorization check in Microsoft Azure CycleCloud, identified as CWE-862. An attacker who already has authenticated access can exploit this gap to elevate their privileges over the network and potentially gain administrative control. This flaw enables the attacker to perform actions with higher authority than originally intended, compromising the confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects Microsoft Azure CycleCloud version 8.9.1. This is the only explicitly referenced version; no other affected versions are listed in the available data.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests that the exploitation probability is low but not negligible. The flaw is not currently listed in the CISA KEV catalog. The likely attack vector is through network access to the CycleCloud services, where the lack of authorization checks in authorized API calls allows privilege escalation. An attacker who can reach the affected endpoints could exploit this flaw without needing additional assistance, but must already possess some level of authenticated access.
OpenCVE Enrichment