Executive brief
Azure CycleCloud is Microsoft's cloud resource management and orchestration service. An authorized user with network access can exploit a missing authorization check to disclose sensitive information that should be restricted to higher-privileged accounts, potentially exposing operational data or credentials.
Technical details
A missing authorization vulnerability exists in Azure CycleCloud where insufficient access control on certain API endpoints or operations allows an authenticated user to retrieve information beyond their intended privilege scope. The vulnerability requires network connectivity and valid authentication credentials, but does not require elevated privileges to exploit. An attacker can read sensitive data such as configuration details, cluster information, or other restricted operational data. A fix is available from Microsoft via security updates.
Affected products
- Microsoft Azure CycleCloud
Timeline
- 2026-08-11: disclosed