CVE-2026-65806: Azure CycleCloud Information Disclosure Vulnerability
Azure CycleCloud Information Disclosure Vulnerability
Other sources
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65806?
The severity of CVE-2026-65806 is medium, with a score of 6.5.
How does CVE-2026-65806 affect Azure CycleCloud?
CVE-2026-65806 allows an authorized attacker to disclose sensitive information over a network due to missing authorization in Azure CycleCloud.
What kind of information can be disclosed due to CVE-2026-65806?
CVE-2026-65806 can lead to the disclosure of sensitive information depending on the specific configurations and data handled by Azure CycleCloud.
How do I fix CVE-2026-65806?
To mitigate CVE-2026-65806, ensure that the latest security updates and patches are applied to Azure CycleCloud.
What versions of Azure CycleCloud are affected by CVE-2026-65806?
CVE-2026-65806 affects Microsoft Azure CycleCloud version 8.9.2 and potentially earlier versions.