Microsoft Silent Patch for Azure Backup Vulnerability Raises Concerns

Microsoft Silent Patch for Azure Backup Vulnerability Raises Concerns

First seen 16 May 2026, 21:19 UTC Bleepingcomputerolearysec.comScworldcwe.mitre.orglearn.microsoft.com 90% similarity 66.0

Article Content

Browse articles
ThreatCluster

A critical privilege escalation vulnerability in Azure Backup for AKS was discovered by researcher Justin O'Leary in March 2026, allowing users with the 'Backup Contributor' role to gain cluster-admin access without prior permissions. Microsoft rejected the vulnerability report, claiming it required existing administrator access, a statement O'Leary disputes. CERT/CC validated the vulnerability as VU#284781 on April 16, 2026, but Microsoft later recommended against issuing a CVE. On May 12, 2026, O'Leary confirmed that Microsoft had silently patched the vulnerability, which now requires manual configuration for Trusted Access. The lack of a CVE means organizations that had the vulnerable role assigned remain unaware of their exposure. The vulnerability is classified as a Confused Deputy vulnerability (CWE-441), affecting Azure Backup for AKS systems.

Key Points: • A privilege escalation flaw in Azure Backup for AKS allows unauthorized cluster-admin access. • Microsoft rejected the vulnerability report, claiming it required existing admin access, which is incorrect. • The vulnerability was silently patched, raising concerns about transparency and customer protection.

ThreatCluster AI

Timeline

2026-03-17
Vulnerability reported to Microsoft
Justin O'Leary reported a critical privilege escalation flaw in Azure Backup for AKS to Microsoft.
BleepingComputer
2026-04-13
Microsoft rejects vulnerability report
Microsoft claimed the issue only involved obtaining admin access where it already existed, misrepresenting the flaw.
BleepingComputer
2026-04-16
CERT/CC validates vulnerability
CERT/CC independently confirmed the vulnerability and assigned it identifier VU#284781.
olearysec.com
2026-05-04
Microsoft recommends against CVE assignment
Microsoft's Lisa Olson emailed MITRE, falsely claiming the vulnerability required existing admin access.
olearysec.com
2026-05-12
Silent patch confirmed
O'Leary confirmed that Microsoft had silently patched the vulnerability without issuing a CVE.
olearysec.com

Community

Browse all →

Tracked Entities in This Story