AI description
CVE-2026-62835 is an information disclosure vulnerability affecting Online Services, including the Azure Portal, stemming from improper authorization. This flaw allows unauthorized attackers to disclose sensitive information across a network. The vulnerability is rooted in inadequate validation of user permissions and session management mechanisms within the authorization process. Attackers can exploit this weakness to bypass legitimate access controls and retrieve data that should otherwise be restricted, often through insufficient input validation in API endpoints or web interfaces.
- Description
- Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- CNA Tags
- exclusively-hosted-service
- Products
- azure_portal
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- secure@microsoft.com
- CWE-285
- Hype score
- Not currently trending
🚨*CVE* CVE-2026-62835 Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. https://t.co/TL6pZ7Hd9p ----- Traducción: CVE-2026-62835 Autorización incorrecta en Azure Portal permite a un atacante… https://t.co/utmtNg
@infoflowcloud
25 Jul 2026
39 Impressions
1 Retweet
1 Like
1 Bookmark
0 Replies
0 Quotes
🚨Critical - Azure Portal Improper Authorization Information Disclosure (CVE-2026-62835) Microsoft disclosed an improper authorization flaw in the Azure Portal that allows an unauthorized attacker to disclose information over the network. The vector is unauthenticated,
@UpwindMDR
24 Jul 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer htt
@DarkWebInformer
24 Jul 2026
7185 Impressions
10 Retweets
25 Likes
12 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-62835 — CVSS 9.3/10 █████████░ Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/QVu0s5KET8
@OrizonCyber
24 Jul 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:azure_portal:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F32E13E9-F5FD-431A-BC3C-0A20D303E1FC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]