Skip to content
Microsoft Silent Patch for Azure Backup Vulnerability Raises Concerns

Microsoft Silent Patch for Azure Backup Vulnerability Raises Concerns

First seen 16 May 2026, 21:19 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 17, 2026 at 20:21 UTC
  • A privilege escalation flaw in Azure Backup for AKS allows unauthorized cluster-admin access.
  • Microsoft rejected the vulnerability report, claiming it required existing admin access, which is incorrect.
  • The vulnerability was silently patched, raising concerns about transparency and customer protection.

A critical privilege escalation vulnerability in Azure Backup for AKS was discovered by researcher Justin O'Leary in March 2026, allowing users with the 'Backup Contributor' role to gain cluster-admin access without prior permissions. Microsoft rejected the vulnerability report, claiming it required existing administrator access, a statement O'Leary disputes. CERT/CC validated the vulnerability as VU#284781 on April 16, 2026, but Microsoft later recommended against issuing a CVE. On May 12, 2026, O'Leary confirmed that Microsoft had silently patched the vulnerability, which now requires manual configuration for Trusted Access. The lack of a CVE means organizations that had the vulnerable role assigned remain unaware of their exposure. The vulnerability is classified as a Confused Deputy vulnerability (CWE-441), affecting Azure Backup for AKS systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 126d ago How this analysis works

Timeline

2026-03-17
Vulnerability reported to Microsoft
Justin O'Leary reported a critical privilege escalation flaw in Azure Backup for AKS to Microsoft.
BleepingComputer
2026-04-13
Microsoft rejects vulnerability report
Microsoft claimed the issue only involved obtaining admin access where it already existed, misrepresenting the flaw.
BleepingComputer
2026-04-16
CERT/CC validates vulnerability
CERT/CC independently confirmed the vulnerability and assigned it identifier VU#284781.
olearysec.com
2026-05-04
Microsoft recommends against CVE assignment
Microsoft's Lisa Olson emailed MITRE, falsely claiming the vulnerability required existing admin access.
olearysec.com
2026-05-12
Silent patch confirmed
O'Leary confirmed that Microsoft had silently patched the vulnerability without issuing a CVE.
olearysec.com

More articles in this cluster (5)

Following this threat?

Track Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed