Junglewise Threat Intelligence

CVE-2026-32173: Microsoft Azure SRE Agent improper authentication in SignalR Hub

CVE-2026-32173 · Severity: high · CVSS 8.6 · Published 2026-04-03

Vendors: Microsoft.

Executive brief

A security flaw in the Microsoft Azure SRE Agent Gateway could allow unauthorized individuals to access sensitive information over the network. This component is part of Microsoft's site reliability engineering infrastructure, and an exploit could lead to the exposure of internal operational data. There is no evidence that this vulnerability has been used in active attacks.

Technical details

A vulnerability classified as improper authentication (CWE-287) and incorrect authorization (CWE-863) exists in the Azure SRE Agent Gateway's SignalR Hub. An unauthenticated attacker can exploit this flaw over a network without any user interaction. The root cause is a failure to properly validate identity or permissions when accessing the SignalR communication channel. Successful exploitation allows for unauthorized information disclosure, potentially exposing sensitive telemetry or system data. Microsoft has categorized this as an exclusively hosted service vulnerability, implying the fix is managed on the service provider side.

Affected products

  • Microsoft Azure SRE Agent Gateway - SignalR Hub All versions

Timeline

  • 2026-04-02: disclosed
  • 2026-04-03: advisory

References