ZeroHour

CVE-2026-69854

large

Improper Authentication in Spring Cloud Azure Enables Network Privilege Elevation

CVSS 3.1
9.0 critical
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-69854 is an improper authentication flaw (CWE-287) in Microsoft's Spring Cloud Azure, the integration library that connects Java/Spring Boot applications to Azure cloud services. A remote, unauthenticated attacker can trigger flawed authentication checks over the network; no privileges or user interaction are required, but the attack carries high complexity per the CVSS score. Successful exploitation allows privilege elevation, with high confidentiality, integrity, and availability impact and a changed scope, meaning the attacker gains authority beyond the intended application trust boundary. Applications built with the affected Spring Cloud Azure components are affected. There is no known exploitation in the wild, no public proof-of-concept, and a low EPSS score (0.6%), and the fix appears to ship with Microsoft's September 2026 Patch Tuesday.

What to do: Upgrade Spring Cloud Azure to the fixed release identified in Microsoft's September 2026 Patch Tuesday advisory, since the available data does not include specific fixed version numbers. Prioritize internet-facing Spring Boot applications that rely on the library for Azure authentication, review your dependency tree for the vulnerable component, and monitor authentication logs for anomalies until patched.

Affected
Microsoft Spring Cloud Azure
Estimated exposure
large≈hundreds of thousands of application instances (order-of-magnitude estimate; no public install counts available) — Spring Cloud Azure is Microsoft's standard library for adding Azure/Entra ID authentication to Java Spring Boot applications and is widely embedded in enterprise Java deployments, plausibly affecting hundreds of thousands of application…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs