Critical Azure Automation Flaw Allows Privilege Escalation

Critical Azure Automation Flaw Allows Privilege Escalation

First seen 27 Jul 2026, 15:06 UTC nvd.nist.govPetrimsrc.microsoft.com 81% similarity 72.6

Article Content

Browse articles
ThreatCluster

Microsoft has patched a critical vulnerability (CVE-2025-29827) in Azure Automation that could allow authorized attackers to elevate privileges and access resources across Azure tenants. Discovered by researcher Shay Shavit and published on May 8, 2025, this flaw has a CVSS score of 9.9 and can be exploited remotely with low-level privileges. Attackers could impersonate other organizations' automation identities, gaining unauthorized access to sensitive data and automated processes. Microsoft has recommended that organizations ensure their Azure Automation environments are updated and configured according to security best practices. The vulnerability stems from improper authorization and can be exacerbated by risky default configurations. Organizations are urged to audit their permissions and follow the principle of least privilege to mitigate risks.

Key Points: • CVE-2025-29827 is a critical privilege escalation vulnerability in Azure Automation. • The flaw allows attackers with low-level access to impersonate other organizations' identities. • Microsoft has released a patch and recommends immediate updates and audits of Azure Automation configurations.

ThreatCluster AI How this analysis works

Timeline

2025-05-08
CVE-2025-29827 published
Microsoft disclosed a critical vulnerability in Azure Automation allowing privilege escalation.
nvd.nist.gov
2026-07-27
Microsoft releases security update
Microsoft addressed the critical vulnerability in Azure Automation and modified default configurations to reduce risk.
Petri

Community

Browse all →