Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
The vulnerability classified as CWE-302 (Authentication Bypass by Assumed-Immutable Data) means that the authentication mechanism relies on data that is incorrectly assumed to be immutable or impossible to forge by an attacker. By manipulating this data, an unauthorized user can bypass identity verification without knowing valid credentials. The attack is possible remotely over the network, with high complexity (AC:H), which suggests the need to meet specific conditions or carefully prepare the request.
Successful exploitation of this vulnerability allows an attacker to escalate privileges in the Azure DevOps environment, potentially gaining full control over resources (confidentiality, integrity, and availability rated as HIGH), including code repositories, CI/CD pipelines, and project configuration.
Apply patches available from the vendor according to references — updates described in the Microsoft Security Response Center guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47158. If immediate patch deployment is not possible, it is recommended to restrict access to Azure DevOps instances at the network level and increase monitoring of authentication logs.
Microsoft Azure DevOps — versions indicated in the vendor references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HMicrosoft Azure Devops
APPMicrosoftall versions
Related vulnerabilities
Ujawnienie wrażliwych informacji w Microsoft Azure DevOps (CVE-2026-42826)
Pominięcie uwierzytelnienia w Azure DevOps — eskalacja uprawnień przez sieć
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges ove...
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)