PT-2026-61937 · Microsoft · Azure Api Management

CVE-2025-66390

·

Published

2026-07-21

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Azure API Management versions prior to 2025-10-17
Description When self-service signup using username and password Basic Authentication is enabled in one tenant, an attacker can reuse the registration flow to target another tenant by modifying the hostname or tenant identifier. This occurs because disabling signup via the user interface does not disable the underlying API endpoint, which continues to accept cross-tenant requests based on the Host header. The supplier has noted that this behavior is considered a configuration or state issue rather than a breach of tenant isolation security boundaries.
Recommendations Update to the version released after 2025-10-17.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66390

Affected Products

Azure Api Management