www.darkreading.com 7/24/2026, 8:30:43 PM · external

Microsoft fixes Azure Automation flaw after CVE-2025-29827 leak

Microsoft fixes Azure Automation flaw after CVE-2025-29827 leak
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE article discusses a critical vulnerability in Microsoft's Azure Automation service that could allow attackers to seize identities of other tenants due to a default public configuration. Discovered by security researcher Shay Shavit, this vulnerability (CVE-2025-29827) has a CVSS score of 9.9 and could enable unauthorized access to sensitive data and resources across a cloud environment. Although Microsoft has updated the default setting, Shavit warns against exposing identities externally.

He emphasizes the importance of considering vulnerabilities within the context of potential exploit chains and highlights the growing significance of identities in cloud security. The piece also references past vulnerabilities and stresses the need for comprehensive security audits of cloud setups.

View Primary Source Via www.darkreading.com

Article by CyberSIXT