CVE-2026-69854 – Spring Cloud Azure Elevation of Privilege Vulnerability
CVSS 9
CRITICAL
Critical - Same Day Deployment
"A stolen path to authentication can turn an untrusted tenant into a doorway to protected business data and operations."
Spring Cloud Azure contains an improper authentication vulnerability that could allow an unauthenticated attacker to elevate privileges over a network. In an affected multi-tenant application, an attacker could use an identity token issued by a tenant they control to obtain an authenticated session. Successful exploitation could expose protected data and allow actions normally restricted to authenticated users. The affected Microsoft product is Spring Cloud Azure.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-287
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.