• News/
  • bleepingcomputer-20260516205544

Microsoft rejects critical Azure vulnerability report, no CVE issued

BleepingComputer
·
Ax Sharma
·
Published May 16, 2026
·
Updated

Editor's note, May 19th 2026: Following publication, CERT/CC contacted BleepingComputer to clarify its handling of this report. CERT/CC did not independently validate or agree that the reported issue constitutes a vulnerability. While the organization assigned the report a VU# identifier (VU#284781) in its VINCE platform, that action reflects intake processing, not a finding of validity. The June 1 disclosure date visible in the researcher's screenshot was auto-generated by VINCE and did not represent a scheduled disclosure. The article has been corrected accordingly. We regret the error. A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and blocking a CVE from being issued. The researcher's report describes a critical privilege escalation flaw that allowed cluster-admin access from the low-privileged "Backup Contributor" role. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that "no product changes were made," despite the researcher documenting new permission checks and failed exploit attempts after disclosure, suggestive of a silent patch. Security researcher Justin O'Leary discovered the security flaw this March, and reported it to Microsoft on March 17. Microsoft Security Response Center (MSRC) rejected the report on April 13, claiming the issue only involved obtaining cluster-admin on a cluster where "the attacker already held administrator access," a characterizati...

Read full article

Affected Software

1 affected component
Microsoft Azure Backup for AKS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Microsoft's rejection of a critical vulnerability report related to Azure services.

2

What security implications are discussed in the article?

The article raises concerns about the lack of a CVE for a reported vulnerability in Microsoft Azure, which could impact user security.

3

Which specific Azure product is mentioned as being affected?

The affected software mentioned is Microsoft Azure Backup for AKS.

4

What action was taken by CERT/CC regarding the vulnerability report?

CERT/CC clarified that they did not validate or agree that the reported issue constitutes a vulnerability.

5

What was Microsoft's response to the reported critical Azure vulnerability?

Microsoft rejected the vulnerability report and did not issue a CVE for it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203