A critical vulnerability in Microsoft's Azure Automation service could have exposed accounts to cross-tenant identity takeovers due to a default setting that had the potential to make account identities become public. Azure Automation is widely used by Microsoft internally and by enterprises running Azure for DevOps, resource deployment, patching, and secrets rotation using scripted runbooks tied to embedded managed identities. Shay Shavit, a senior security researcher on Microsoft's Azure Networking Security Research team, discovered the vulnerability last year and reported it to the Microsoft Security Response Center (MSRC), which issued an advisory. Azure Automation Elevation of Privilege Vulnerability (CVE-2025-29827), which was assigned a CVSS score of 9.9, allows an attacker with access to their own Azure Automation account to breach the trust boundary and assume another tenant's automation identity. This would enable them to create or modify automation scripts and access sensitive configuration data or credentials stored in Azure Automation accounts. A successful attacker could also create, change, or delete resources across an organization's cloud workloads. Shavit tells Dark Reading that there have been no known exploits of the vulnerability, but in his demonstration at next month's Black Hat USA conference in Las Vegas, he plans to show how the default configuration poses a risk to Microsoft and its customers. The default setting for Azure Automation identities is n...
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Dark Reading
·Jeffrey Schwartz
·Published Jul 24, 2026
·Updated
Affected Software
1 affected component
Microsoft Azure Automation
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Microsoft's Azure Automation service that could allow cross-tenant identity takeovers.
2
What security implications are discussed?
The default setting in Azure Automation could expose user accounts to potential public access, leading to identity theft.
3
What products or software are affected?
The affected software is Microsoft Azure Automation.
4
What caused the vulnerability in Azure Automation?
The vulnerability was caused by a default setting that allowed account identities to be publicly accessible.
5
How does this vulnerability impact Azure users?
It poses a significant threat as it could enable unauthorized access to user accounts across different tenants.