Junglewise Threat Intelligence

CVE-2026-47280: Microsoft Azure Resource Manager improper authentication privilege escalation

CVE-2026-47280 · Severity: critical · CVSS 10 · Published 2026-05-22

Executive brief

A critical vulnerability exists in Microsoft Azure Resource Manager, the central management layer for all Azure cloud resources. An unauthorized attacker could exploit this flaw to gain full administrative control over cloud environments without needing any existing credentials. This could lead to total data exposure, service destruction, or unauthorized access to sensitive corporate infrastructure.

Technical details

A critical improper authentication vulnerability (CWE-287) exists in Azure Resource Manager (ARM). The flaw allows an unauthenticated attacker to bypass security controls over the network to achieve full privilege escalation. With a CVSS score of 10.0 and a 'Changed' Scope (S:C), an exploit could allow an attacker to move beyond the ARM management plane to impact other integrated cloud resources. No user interaction or prior privileges are required for exploitation. As ARM is an exclusively hosted service, Microsoft typically manages the remediation on the backend.

Affected products

  • Microsoft Azure Resource Manager (ARM)

Timeline

  • 2026-05-22: disclosed: Initial publication of CVE-2026-47280

References

Related threats