VulnerabilitiesJul 24, 2026
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Azure Automation flaw allowed cross-tenant identity takeover and data access.
Summary
Microsoft has patched a critical vulnerability in Azure Automation that, when chained with other code flaws, allowed attackers to take over identities in other tenants. This could have led to unauthorized access to sensitive data, credentials, and cloud workloads across different Azure environments.
Entities
Azure Automation (product)Microsoft (vendor)identity (technology)cloud (technology)