CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-47158

CVSS 9.0v3.1pub. 2025-07-18upd. 2025-08-14

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-302 (Authentication Bypass by Assumed-Immutable Data) means that the authentication mechanism relies on data that is incorrectly assumed to be immutable or impossible to forge by an attacker. By manipulating this data, an unauthorized user can bypass identity verification without knowing valid credentials. The attack is possible remotely over the network, with high complexity (AC:H), which suggests the need to meet specific conditions or carefully prepare the request.

Impact

Successful exploitation of this vulnerability allows an attacker to escalate privileges in the Azure DevOps environment, potentially gaining full control over resources (confidentiality, integrity, and availability rated as HIGH), including code repositories, CI/CD pipelines, and project configuration.

Mitigation & patch

Apply patches available from the vendor according to references — updates described in the Microsoft Security Response Center guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47158. If immediate patch deployment is not possible, it is recommended to restrict access to Azure DevOps instances at the network level and increase monitoring of authentication logs.

Who is affected

Microsoft Azure DevOps — versions indicated in the vendor references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Azure Devops

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-42826CRITICAL10.0PL ✓same product

Ujawnienie wrażliwych informacji w Microsoft Azure DevOps (CVE-2026-42826)

CVE-2025-29813CRITICAL10.0PL ✓same product

Pominięcie uwierzytelnienia w Azure DevOps — eskalacja uprawnień przez sieć

CVE-2026-23658HIGH8.6same product

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges ove...

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)