-
Notifications
You must be signed in to change notification settings - Fork 70
Open
Labels
additionNew security issue or vulnerabilityNew security issue or vulnerabilityazureIssue related to an Azure serviceIssue related to an Azure service
Description
Summary (give a brief description of the issue)
"an Azure Event Grid System Topic vulnerability allowing us to view Event Subscriptions data for all tenants that had an Event Subscription configured due to a flaw in the filtering mechanism Microsoft used for displaying data to their customers. This vulnerability was disclosed through Microsoft Security Response Center as ‘VULN-162828’ which was classified as ‘Critical’ under the ‘Elevation of Privilege’ topic and later disclosed as ‘CVE-2025-59273’."
References (provide links to blogposts, etc.)
https://thecollective.eu/cross-tenant-event-grid-privilege-escalation-vulnerability/
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
additionNew security issue or vulnerabilityNew security issue or vulnerabilityazureIssue related to an Azure serviceIssue related to an Azure service