« Volver al listado

CVE-2025-66390

Estado: Pendiente de análisisCrítica (9.8)—

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header).

Leer descripción completaMostrar menos

NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). NOTE: The supplier evaluated this report and determined that it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/AC:L/PR:N permite explotar API expuesta sin autenticación (T1190). Atacante crea cuentas en tenant destino modificando Host header, obteniendo credenciales válidas (T1078) y creando nuevas cuentas (T1136).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-66390",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-66390",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-22T15:18:22.488125Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-21T14:16:32.797",
  "references": [
    {
      "url": "https://github.com/bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass/security/advisories/GHSA-vcwf-73jp-r7mv",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/bountyyfi/Azure-APIM-Cross-Tenant-Signup-Bypass",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header). NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). NOTE: The supplier evaluated this report and determined that it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation)."
    },
    {
      "lang": "es",
      "value": "En Microsoft Azure API Management hasta el 17-10-2025, cuando el registro de autoservicio (autenticación básica de nombre de usuario/contraseña) está habilitado en el Inquilino A, un atacante puede reutilizar el flujo de registro cambiando el nombre de host o el identificador de inquilino al Inquilino B, incluso cuando el Inquilino B tiene el registro deshabilitado a nivel de la interfaz de usuario. En otras palabras, deshabilitar el registro en la interfaz de usuario no deshabilita el endpoint de la API subyacente (que aún acepta solicitudes entre inquilinos basadas en el encabezado Host). NOTA: El proveedor afirma que evaluaron el informe y determinaron que no cruzaba un límite de seguridad (es decir, el comportamiento observado fue un problema de configuración/estado en lugar de una vulnerabilidad de producto explotable que afectara el aislamiento de inquilinos). NOTA: El proveedor evaluó este informe y determinó que no cruzaba un límite de seguridad (es decir, el comportamiento observado fue un problema de configuración/estado en lugar de una vulnerabilidad de producto explotable que afectara el aislamiento de inquilinos)."
    }
  ],
  "lastModified": "2026-10-05T18:10:00.200",
  "sourceIdentifier": "cve@mitre.org"
}