Impact
The vulnerability is an authenticated IDOR that allows users to read, write, and delete processes and files belonging to other authenticated users. The flaw originates from missing ownership checks on multiple API endpoints, enabling unauthorized access to migration data across users inside the same organization. This results in potential data tampering and privacy breaches for users within the same tenant.
Affected Systems
Microsoft Container Migration Solution Accelerator, version 2.1.2 and earlier. The issue arises in the process and file management APIs of this multi‑service application, which relies on Entra ID authentication but does not enforce proper authorization controls between users.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity risk of unauthorized data access and deletion. The EPSS score is not available, but the lack of a KEV listing suggests no known public exploitation at this time. However, attackers that can authenticate to the system can likely exploit the missing ownership checks by targeting exposed API endpoints, as inferred from the description.
OpenCVE Enrichment