SYS::ONLINE
Wasteland.
Briefs1521
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62825 2026-07-23

CVE-2026-62825: Critical Authentication Bypass in Azure Key Vault Enables Privilege Escalation

"Microsoft has disclosed CVE-2026-62825, a maximum-severity (CVSS 10.0) improper authentication flaw in Azure Key Vault that lets an unauthenticated attacker elevate privileges over the network."

Microsoft has disclosed CVE-2026-62825, a maximum-severity (CVSS 10.0) improper authentication flaw in Azure Key Vault that lets an unauthenticated attacker elevate privileges over the network.

What Is It

CVE-2026-62825 is an improper authentication vulnerability (CWE-287) in Microsoft Azure Key Vault. According to Microsoft, the flaw "allows an unauthorized attacker to elevate privileges over a network." It carries a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H, meaning it is network-exploitable, requires low attack complexity, needs no privileges, and requires no user interaction. The scope is marked as changed, and impact to both integrity and availability is rated HIGH.

Why It Matters

Azure Key Vault is a cloud service used to store and manage secrets, encryption keys, and certificates. An authentication weakness reaching a perfect 10.0 score is significant: an attacker on the network can abuse it without credentials or user interaction, and the "scope changed" rating indicates the impact can extend beyond the initially vulnerable component. The HIGH integrity and availability impact means an attacker could alter protected resources and disrupt the service. Microsoft tags the CVE as an "exclusively-hosted-service," indicating it affects the managed cloud offering.

What's Vulnerable

No specific affected CPE configurations were provided in the NVD record.

Patch Status

The supplied source material does not include a CISA KEV entry, so there is no confirmation of active exploitation in the provided data. No specific remediation steps or required actions are included in the supplied NVD record. As an exclusively-hosted service, remediation for Azure Key Vault is typically managed by Microsoft; refer to the Microsoft Security Response Center update guide for authoritative status.

Sources