CVE-2026-62874: Azure Billing Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Azure Billing Elevation of Privilege Vulnerability
Other sources
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Azure Billing
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·11:04 PM
Data Sourced
via MITRE·11:04 PM
DescriptionSeverity
Frequently Asked Questions
1
What access and interaction are required to exploit this issue?
The vulnerability is network-reachable and has low attack complexity. It requires no prior privileges and no user interaction.
2
What could a successful attacker do?
A successful exploit could allow an unauthorized attacker to elevate privileges. The listed impact includes high confidentiality and integrity impact, with low availability impact, and the impact may extend beyond the vulnerable security scope.
3
Is exploitation known to be occurring?
The exploit code maturity is listed as unproven, so the provided data does not indicate confirmed public exploitation.
4
Is a vendor remediation available?
The remediation level is listed as an official fix.