Executive brief
Azure Key Vault is a cloud service used to securely store and manage sensitive information such as passwords, encryption keys, and certificates. A critical security flaw allows an unauthenticated attacker to bypass identity checks and gain elevated permissions over the network. This could allow an attacker to modify or delete sensitive cryptographic keys and secrets, potentially leading to a complete loss of data integrity or service availability for applications relying on the vault.
Technical details
A vulnerability classified as improper authentication (CWE-287) exists within Microsoft Azure Key Vault. The flaw allows a remote, unauthenticated attacker to bypass security controls and elevate their privileges within the service environment. According to the CVSS vector, the attack can be carried out over the network with low complexity and requires no user interaction. Successful exploitation grants the attacker high-impact capabilities to modify or destroy resources (Integrity and Availability), though the specific vector indicates no direct impact on Confidentiality. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly to the Azure infrastructure.
Affected products
- Microsoft Azure Key Vault All versions
Timeline
- 2026-07-24: advisory: Initial disclosure by Microsoft and NVD