Description
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

This vulnerability results from credentials that are insufficiently protected within Azure CycleCloud. An attacker who already has authorized access can exploit this weakness to retrieve sensitive information over the network, potentially aiding further compromise or data exfiltration. The flaw is associated with CWE-522, indicating that credential information may be exposed during normal operation.

Affected Systems

Microsoft Azure CycleCloud version 8.9.2 is known to be affected. No other product versions were listed in the CNA data, so the scope is limited to this specific release.

Risk and Exploitability

The CVSS score of 7.7 classifies the vulnerability as high. EPSS data is not available, so the exact likelihood of exploitation cannot be quantified, but the vulnerability is not currently listed in CISA’s KEV catalog, suggesting it has not yet been widely employed in the wild. Since the attack vector requires an attacker who has already bypassed initial controls, the risk is concentrated on systems where privileged or authorized accounts exist. Remediation is recommended before the vulnerability becomes a vector for broader attacks.

Generated by OpenCVE AI on September 9, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Azure CycleCloud to the latest patched version that resolves the credential exposure, following instructions on Microsoft’s security update guide.
  • Enforce multi‑factor authentication and enforce the principle of least privilege for all accounts that interact with Azure CycleCloud services.
  • Configure network segmentation to limit exposure of credential‑handling endpoints and ensure all traffic is encrypted.

Generated by OpenCVE AI on September 9, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Title Azure CycleCloud Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft azure Cyclecloud
Weaknesses CWE-522
CPEs cpe:2.3:a:microsoft:azure_cyclecloud:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Cyclecloud
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Cyclecloud
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:32.114Z

Reserved: 2026-08-21T17:26:55.613Z

Link: CVE-2026-77909

cve-icon Vulnrichment

Updated: 2026-09-08T20:20:50.892Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:20:41.117

Modified: 2026-09-08T21:18:40.267

Link: CVE-2026-77909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T01:15:17Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials