CVE-2025-29827
CVSS 9.9 CRITICAL: improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. EPSS 2% (74th percentile).
Vulnerabilities & Exploits · Misconfiguration
Azure Automation’s default identity exposure let a valid account cross a trust boundary and act with another tenant’s managed identity. The standard view of this as an automation bug misses the larger problem: once that identity is taken over, the attacker can inherit the privileges behind runbooks and move from one account into cloud control and sensitive secrets.
Microsoft fixed CVE-2025-29827 after researchers found that the account identity endpoint was publicly reachable by default. With an ordinary Azure Automation account, an attacker could assume another tenant’s automation identity and then create, modify, or delete resources, or read configuration data and credentials tied to that identity.
The practical risk is broader than one misconfigured automation account. In environments that use Azure Automation for deployment, patching, or secret rotation, a compromised identity can become a standing control path into the workloads it is trusted to manage.
1 source · Jul 24
CVSS 9.9 CRITICAL: improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. EPSS 2% (74th percentile).
Dark Reading
Default Azure Automation Setting Enables Cross-Tenant Attacks
A critical Azure Automation bug lets an attacker with a valid account hijack identities and access other tenants' data, credentials, and cloud workloads.
originalPart of the PlainSec briefing for 2026-07-24
Every edition of this story: Azure Automation Defaults Cross Tenant Identity Trust