ZeroHour

CVE-2026-62874

mass

Privilege Escalation via Insufficient Data Authenticity Verification in Microsoft Azure Billing

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-62874 is a critical flaw (CWE-345, Insufficient Verification of Data Authenticity) in Microsoft's Azure Billing service, which fails to properly validate the authenticity of data it accepts. An unauthenticated remote attacker can trigger the flaw over a network with no privileges required and no user interaction, by supplying forged or spoofed data that the service trusts. Successful exploitation elevates the attacker's privileges with a scope change beyond the vulnerable component, yielding high confidentiality and integrity impact and low availability impact — potentially allowing access to or manipulation of billing/subscription data. Effectively every organization with an Azure subscription that uses Azure Billing is in scope, since it is a core Azure service patched server-side by Microsoft. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known at this time.

What to do: Because Azure Billing is a Microsoft-managed cloud service, remediation is delivered service-side — verify your tenant has received the update per Microsoft's advisory and confirm no tenant action is required. In the meantime, review Azure Activity Logs, billing/role assignment changes, and billing administrator role memberships for signs of abuse, and follow least-privilege on Billing and Subscription admin roles. Monitor Microsoft's advisory for updated indicators or guidance.

Affected
Microsoft Azure Billing (Azure cloud service)Cloud service; no version numbers apply — all tenants using Azure Billing at the time of disclosure (fixed via Microsoft service-side update)
Estimated exposure
massmillions of Azure tenants/subscriptions (Azure Billing is a default core service used by virtually all Azure customers) — Azure is one of the largest cloud platforms, publicly reported to serve millions of customers including the majority of the Fortune 500, and Azure Billing is integral to every subscription, so exposure is estimated at an order of magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.