Junglewise Threat Intelligence

CVE-2026-62835: Microsoft Azure Portal improper authorization information disclosure

CVE-2026-62835 · Severity: critical · CVSS 9.3 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in the Microsoft Azure Portal, the primary management interface for Microsoft's cloud services. This flaw allows an unauthorized person to access sensitive information over the internet without needing a password or user interaction. Such an exploit could lead to the exposure of confidential configuration data or administrative details, potentially compromising the security of cloud operations.

Technical details

An improper authorization vulnerability (CWE-285) exists in the Microsoft Azure Portal. The flaw allows a remote, unauthenticated attacker to access sensitive information via the network without any user interaction. According to the CVSS metrics, the vulnerability has a high impact on confidentiality and a low impact on availability, with a scope change indicating that the exploit may affect resources beyond the immediate portal component. As an exclusively hosted service, Microsoft typically manages the deployment of fixes for the Azure Portal directly.

Affected products

  • Microsoft Azure Portal All versions

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory: MSRC and NVD advisory published

References

Related threats