CVE Tools

Default Azure Automation Setting Enables Cross-Tenant Identity Takeover

Dark ReadingBy Jeffrey Schwartz

PatchAzure Automation

Our summary

Microsoft has addressed a critical vulnerability in its Azure Automation service that could have allowed attackers to perform cross-tenant identity takeovers. The flaw, tracked as CVE-2025-29827 and rated with a CVSS score of 9.9, stemmed from a default setting that unintentionally exposed automation account identities. An attacker with access to their own Azure Automation account could exploit this to breach trust boundaries and impersonate another tenant's identity, enabling unauthorized script modifications and access to sensitive data. Microsoft researcher Shay Shavit discovered the issue and reported it to MSRC, who issued an advisory. Although no known exploits were observed, the default configuration remains a key concern. Organizations are advised to audit their automation account configurations and limit external exposure unless necessary.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store