Skip to main content

Microsoft Azure Portal Unauthenticated Information Disclosure Server-Side Patched (CVE-2026-62835)

Scope: Microsoft Azure Portal (All Tenants, Exclusively Cloud-Hosted Service)

Severity: Red

Microsoft published CVE-2026-62835 (CVSS 9.3, Critical) on July 24, 2026, disclosing an improper authorization flaw in the Azure Portal that allows an unauthenticated remote attacker with no privileges and no user interaction required to bypass access controls and retrieve sensitive information stored in the portal over the network. The scope change component of the CVSS vector (S:C) indicates the impact extends beyond the directly vulnerable component, meaning exposed data may belong to resources or tenants outside the attacker's own context. Microsoft manages remediation for the Azure Portal as a cloud service and has confirmed a server-side fix has been applied, meaning no direct patching action is required from tenant administrators. Organizations using Azure should however verify there are no active anomalous access attempts in Azure Monitor and Entra ID sign-in logs from the July 23 to 24 window, enable Microsoft Defender for Cloud alerts for unauthorized API access, and monitor the MSRC advisory page for any expanded scope disclosures as Microsoft releases further details.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.