CVE Tools
Back to feed
Patch released Azure Automation cloud Microsoft privilege-escalation

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Dark Reading·By Jeffrey Schwartz··3 min read
CVE Tools coverage

Microsoft has addressed a critical vulnerability in its Azure Automation service that could have allowed attackers to perform cross-tenant identity takeovers. The flaw, tracked as CVE-2025-29827 and rated with a CVSS score of 9.9, stemmed from a default setting that unintentionally exposed automation account identities. An attacker with access to their own Azure Automation account could exploit this to breach trust boundaries and impersonate another tenant's identity, enabling unauthorized script modifications and access to sensitive data. Microsoft researcher Shay Shavit discovered the issue and reported it to MSRC, who issued an advisory. Although no known exploits were observed, the default configuration remains a key concern. Organizations are advised to audit their automation account configurations and limit external exposure unless necessary.