• News/
  • darkreading-20260724124816

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Dark Reading
·
Jeffrey Schwartz
·
Published Jul 24, 2026
·
Updated

A critical vulnerability in Microsoft's Azure Automation service could have exposed accounts to cross-tenant identity takeovers due to a default setting that had the potential to make account identities become public. Azure Automation is widely used by Microsoft internally and by enterprises running Azure for DevOps, resource deployment, patching, and secrets rotation using scripted runbooks tied to embedded managed identities. Shay Shavit, a senior security researcher on Microsoft's Azure Networking Security Research team, discovered the vulnerability last year and reported it to the Microsoft Security Response Center (MSRC), which issued an advisory. Azure Automation Elevation of Privilege Vulnerability (CVE-2025-29827), which was assigned a CVSS score of 9.9, allows an attacker with access to their own Azure Automation account to breach the trust boundary and assume another tenant's automation identity. This would enable them to create or modify automation scripts and access sensitive configuration data or credentials stored in Azure Automation accounts. A successful attacker could also create, change, or delete resources across an organization's cloud workloads. Shavit tells Dark Reading that there have been no known exploits of the vulnerability, but in his demonstration at next month's Black Hat USA conference in Las Vegas, he plans to show how the default configuration poses a risk to Microsoft and its customers. The default setting for Azure Automation identities is n...

Read full article

Affected Software

1 affected component
Microsoft Azure Automation
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Microsoft's Azure Automation service that could allow cross-tenant identity takeovers.

2

What security implications are discussed?

The default setting in Azure Automation could expose user accounts to potential public access, leading to identity theft.

3

What products or software are affected?

The affected software is Microsoft Azure Automation.

4

What caused the vulnerability in Azure Automation?

The vulnerability was caused by a default setting that allowed account identities to be publicly accessible.

5

How does this vulnerability impact Azure users?

It poses a significant threat as it could enable unauthorized access to user accounts across different tenants.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203