Executive brief
Azure Portal is the web interface used by Microsoft cloud customers to manage cloud infrastructure and services. An attacker could inject malicious code that executes in users' browsers, enabling account takeover, credential theft, or unauthorized changes to cloud resources without user awareness.
Technical details
Stored or reflected cross-site scripting (XSS) vulnerability in Azure Portal allows injection of untrusted input into web pages without proper sanitization. An attacker on the network can craft a malicious request or link that, when accessed by an authenticated user, executes arbitrary JavaScript in the victim's browser context, leading to session hijacking, credential harvesting, or malicious actions on cloud resources. Patches are available from Microsoft.
Affected products
- Microsoft Azure Portal
Timeline
- 2026-09-18: disclosed