PT-2026-61937 · Microsoft · Azure Api Management
CVE-2025-66390
·
Published
2026-07-21
·
Updated
2026-09-10
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Azure API Management versions prior to 2025-10-17
Description
When self-service signup using username and password Basic Authentication is enabled in one tenant, an attacker can reuse the registration flow to target another tenant by modifying the hostname or tenant identifier. This occurs because disabling signup via the user interface does not disable the underlying API endpoint, which continues to accept cross-tenant requests based on the
Host header. The supplier has noted that this behavior is considered a configuration or state issue rather than a breach of tenant isolation security boundaries.Recommendations
Update to the version released after 2025-10-17.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azure Api Management