Executive brief
A critical vulnerability exists in Microsoft Azure Resource Manager, the central management layer for all Azure cloud resources. An unauthorized attacker could exploit this flaw to gain full administrative control over cloud environments without needing any existing credentials. This could lead to total data exposure, service destruction, or unauthorized access to sensitive corporate infrastructure.
Technical details
A critical improper authentication vulnerability (CWE-287) exists in Azure Resource Manager (ARM). The flaw allows an unauthenticated attacker to bypass security controls over the network to achieve full privilege escalation. With a CVSS score of 10.0 and a 'Changed' Scope (S:C), an exploit could allow an attacker to move beyond the ARM management plane to impact other integrated cloud resources. No user interaction or prior privileges are required for exploitation. As ARM is an exclusively hosted service, Microsoft typically manages the remediation on the backend.
Affected products
- Microsoft Azure Resource Manager (ARM)
Timeline
- 2026-05-22: disclosed: Initial publication of CVE-2026-47280