Executive brief
Microsoft Azure API Management is a service used by organizations to publish and manage APIs for their developers. A security issue allows unauthorized users to create accounts on a company's developer portal even if the administrator has disabled the 'sign-up' feature in the settings. This could allow outsiders to view internal API documentation or potentially access sensitive API keys that were intended only for authorized internal users.
Technical details
This vulnerability is an improper access control issue (CWE-284) in the Azure API Management (APIM) Developer Portal. When Basic Authentication (username/password) is enabled on any tenant (Tenant A), the underlying registration API endpoint remains active and fails to properly validate the 'Host' header or tenant identifier against the UI-level 'signup disabled' state of a target tenant (Tenant B). An unauthenticated attacker can intercept a signup request to a portal where registration is allowed and modify the Host header to point to a target portal where registration is supposedly disabled. This results in unauthorized account creation on the target tenant, potentially granting access to internal API documentation and subscription keys. Microsoft has reportedly classified this behavior as 'by design,' and no patch is available; the recommended mitigation is to remove the 'Username and password' identity provider and use Azure AD exclusively.
Affected products
- Microsoft Azure API Management Developer Portal All versions through 2025-10-17
Timeline
- 2025-09-30: disclosed: Initial report to Microsoft Security Response Center (MSRC)
- 2025-11-26: advisory: Public disclosure by researcher via GitHub/GHSA
- 2026-07-21: advisory: NVD publication of CVE-2025-66390