Executive brief
Microsoft Azure Privileged Identity Management (PIM) is a service used to manage, control, and monitor access to important resources in an organization. A security flaw in this service allows an attacker who already has basic user access to bypass authorization checks and gain higher-level administrative privileges. This could lead to unauthorized access to sensitive corporate data and full control over cloud resources.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Azure Privileged Identity Management (PIM) due to the use of user-controlled keys in authorization checks. An attacker with low-privileged authenticated access can manipulate these keys over the network to bypass security restrictions. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining full administrative control over the affected environment. The vulnerability is rated with a CVSS 3.1 score of 8.8, reflecting high impact on confidentiality, integrity, and availability. As this is an exclusively hosted service, Microsoft typically applies fixes directly to the Azure environment.
Affected products
- Microsoft Azure Privileged Identity Management (PIM)
Timeline
- 2026-05-22: disclosed: Initial disclosure by Microsoft and NVD publication.