Executive brief
Microsoft Azure HorizonDB, a cloud-hosted database service, contains a critical vulnerability that allows unauthorized users to bypass security checks. By spoofing their identity, an attacker can gain administrative control over the database system without needing a password. This could lead to significant data corruption, unauthorized modifications, or a complete loss of service availability.
Technical details
A critical authentication bypass vulnerability (CWE-290) exists in Microsoft Azure HorizonDB due to improper verification of identity claims, allowing for spoofing. An unauthenticated attacker can exploit this over the network with low complexity and no user interaction required. Successful exploitation allows the attacker to bypass authentication mechanisms and elevate privileges to a level that permits high-impact integrity and availability compromises. The vulnerability is specific to the HorizonDB hosted service, and Microsoft has addressed the issue within the Azure environment.
Affected products
- Microsoft Azure HorizonDB
Timeline
- 2026-06-04: advisory: Initial disclosure by Microsoft and NVD publication.