CVE-2026-69854: Spring Cloud Azure Elevation of Privilege Vulnerability
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
Other sources
Spring Cloud Azure Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.4.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is network-accessible and requires no prior privileges or user interaction. Exploitation is rated as high complexity.
What could a successful attacker do?
A successful unauthorized attacker could elevate privileges. The reported impact includes high confidentiality, integrity, and availability impact, and the scope may extend beyond the vulnerable component.
How can I determine whether my deployment is affected?
The provided information identifies Microsoft Spring Cloud Azure as the affected software but does not provide affected versions, fixed versions, configuration conditions, or detection indicators. Review the vendor advisory for version and remediation details.