Editor's note, May 19th 2026: Following publication, CERT/CC contacted BleepingComputer to clarify its handling of this report. CERT/CC did not independently validate or agree that the reported issue constitutes a vulnerability. While the organization assigned the report a VU# identifier (VU#284781) in its VINCE platform, that action reflects intake processing, not a finding of validity. The June 1 disclosure date visible in the researcher's screenshot was auto-generated by VINCE and did not represent a scheduled disclosure. The article has been corrected accordingly. We regret the error. A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and blocking a CVE from being issued. The researcher's report describes a critical privilege escalation flaw that allowed cluster-admin access from the low-privileged "Backup Contributor" role. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that "no product changes were made," despite the researcher documenting new permission checks and failed exploit attempts after disclosure, suggestive of a silent patch. Security researcher Justin O'Leary discovered the security flaw this March, and reported it to Microsoft on March 17. Microsoft Security Response Center (MSRC) rejected the report on April 13, claiming the issue only involved obtaining cluster-admin on a cluster where "the attacker already held administrator access," a characterizati...
Microsoft rejects critical Azure vulnerability report, no CVE issued
BleepingComputer
·Ax Sharma
·Published May 16, 2026
·Updated
Affected Software
1 affected component
Microsoft Azure Backup for AKS
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft's rejection of a critical vulnerability report related to Azure services.
2
What security implications are discussed in the article?
The article raises concerns about the lack of a CVE for a reported vulnerability in Microsoft Azure, which could impact user security.
3
Which specific Azure product is mentioned as being affected?
The affected software mentioned is Microsoft Azure Backup for AKS.
4
What action was taken by CERT/CC regarding the vulnerability report?
CERT/CC clarified that they did not validate or agree that the reported issue constitutes a vulnerability.
5
What was Microsoft's response to the reported critical Azure vulnerability?
Microsoft rejected the vulnerability report and did not issue a CVE for it.