Microsoft Addresses Critical Azure Automation Vulnerability CVE-2025-29827

Microsoft Addresses Critical Azure Automation Vulnerability CVE-2025-29827

First seen 27 Jul 2026, 15:06 UTC nvd.nist.govPetriFeeds.4SysopsSecure-IssForkast.News+2 89% similarity 70.5

Article Content

Browse articles
ThreatCluster

Microsoft has fixed a critical vulnerability in Azure Automation, tracked as CVE-2025-29827, which could allow authorized attackers to elevate privileges and access resources across Azure tenants. Discovered by Shay Shavit and reported in May 2025, the flaw has a CVSS score of 9.9 and stems from improper authorization in the service. Attackers could exploit this vulnerability remotely with low-level privileges, potentially impersonating other organizations' automation identities. Microsoft has updated the default configurations and recommends organizations to verify their Azure Automation accounts and permissions. The flaw could be combined with misconfigurations to cross trust boundaries between Azure tenants, posing a significant risk to sensitive cloud resources. Organizations are advised to apply the latest security updates and follow best practices to mitigate risks.

Key Points: • CVE-2025-29827 is a critical privilege escalation vulnerability in Azure Automation. • Attackers could exploit the flaw to access resources across Azure tenants with low-level privileges. • Microsoft has released security updates and changed default configurations to mitigate the risk.

ThreatCluster AI How this analysis works

Timeline

2025-05-08
CVE-2025-29827 published
Microsoft disclosed a critical vulnerability in Azure Automation allowing privilege escalation.
nvd.nist.gov
2026-07-27
Microsoft releases fix for Azure Automation flaw
Microsoft addressed CVE-2025-29827 and changed default configurations to enhance security.
Petri
2026-07-27
Organizations advised to verify Azure Automation accounts
Microsoft recommends that organizations check their automation accounts and permissions following the fix.
Feeds.4Sysops

Community

Browse all →