Junglewise Threat Intelligence

CVE-2026-62825: Microsoft Azure Key Vault improper authentication privilege escalation

CVE-2026-62825 · Severity: critical · CVSS 10 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

Azure Key Vault is a cloud service used to securely store and manage sensitive information such as passwords, encryption keys, and certificates. A critical security flaw allows an unauthenticated attacker to bypass identity checks and gain elevated permissions over the network. This could allow an attacker to modify or delete sensitive cryptographic keys and secrets, potentially leading to a complete loss of data integrity or service availability for applications relying on the vault.

Technical details

A vulnerability classified as improper authentication (CWE-287) exists within Microsoft Azure Key Vault. The flaw allows a remote, unauthenticated attacker to bypass security controls and elevate their privileges within the service environment. According to the CVSS vector, the attack can be carried out over the network with low complexity and requires no user interaction. Successful exploitation grants the attacker high-impact capabilities to modify or destroy resources (Integrity and Availability), though the specific vector indicates no direct impact on Confidentiality. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly to the Azure infrastructure.

Affected products

  • Microsoft Azure Key Vault All versions

Timeline

  • 2026-07-24: advisory: Initial disclosure by Microsoft and NVD

References