Skip to content
Microsoft Addresses Critical Azure Automation Vulnerability CVE-2025-29827

Microsoft Addresses Critical Azure Automation Vulnerability CVE-2025-29827

First seen 27 Jul 2026, 15:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 28, 2026 at 13:37 UTC
  • CVE-2025-29827 is a critical privilege escalation vulnerability in Azure Automation.
  • Attackers could exploit the flaw to access resources across Azure tenants with low-level privileges.
  • Microsoft has released security updates and changed default configurations to mitigate the risk.

Microsoft has fixed a critical vulnerability in Azure Automation, tracked as CVE-2025-29827, which could allow authorized attackers to elevate privileges and access resources across Azure tenants. Discovered by Shay Shavit and reported in May 2025, the flaw has a CVSS score of 9.9 and stems from improper authorization in the service. Attackers could exploit this vulnerability remotely with low-level privileges, potentially impersonating other organizations' automation identities. Microsoft has updated the default configurations and recommends organizations to verify their Azure Automation accounts and permissions. The flaw could be combined with misconfigurations to cross trust boundaries between Azure tenants, posing a significant risk to sensitive cloud resources. Organizations are advised to apply the latest security updates and follow best practices to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2025-05-08
CVE-2025-29827 published
Microsoft disclosed a critical vulnerability in Azure Automation allowing privilege escalation.
nvd.nist.gov
2026-07-27
Microsoft releases fix for Azure Automation flaw
Microsoft addressed CVE-2025-29827 and changed default configurations to enhance security.
Petri
2026-07-27
Organizations advised to verify Azure Automation accounts
Microsoft recommends that organizations check their automation accounts and permissions following the fix.
Feeds.4Sysops

More articles in this cluster (14)

Following this threat?

Track Microsoft and CVE-2025-29827 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed