Junglewise Threat Intelligence

CVE-2026-58275: Microsoft Azure DNS privilege escalation via missing authorization

CVE-2026-58275 · Severity: critical · CVSS 10 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

A critical security flaw has been identified in Microsoft Azure DNS, the service responsible for managing domain name records in the cloud. This vulnerability allows an unauthorized person to gain elevated control over DNS settings without needing a password or internal access. An attacker could exploit this to redirect web traffic, disrupt online services, or compromise the integrity of the organization's digital infrastructure.

Technical details

A missing authorization vulnerability (CWE-862) exists in Microsoft Azure DNS. The flaw allows a remote, unauthenticated attacker to bypass security checks and elevate their privileges within the DNS service. According to the CVSS vector, the attack is low complexity, requires no user interaction, and has a high impact on both integrity and availability. This could lead to unauthorized modification of DNS records or service disruption. As an exclusively hosted service, Microsoft typically manages the deployment of fixes directly on the Azure platform.

Affected products

  • Microsoft Azure DNS All versions

Timeline

  • 2026-07-24: disclosed: Initial publication of the CVE record.
  • 2026-07-24: advisory: Microsoft MSRC advisory published.

References