CVE-2026-23658
8.6Microsoft · Azure DevOps
Insufficiently protected credentials in Azure DevOps allow an unauthenticated remote attacker to perform unauthorized privilege escalation over a network.
Executive summary
A critical vulnerability in Microsoft Azure DevOps allows unauthenticated attackers to elevate privileges, posing a significant risk to organizational infrastructure.
Vulnerability
This vulnerability involves the insufficient protection of credentials, categorized under CWE-522, which permits an unauthenticated attacker to gain elevated privileges via a network vector.
Business impact
The ability for an unauthenticated user to escalate privileges represents a severe security failure that could lead to full administrative compromise of the DevOps environment. Given the CVSS score of 8.6, this flaw is categorized as High severity and threatens the integrity of software supply chains, potentially resulting in unauthorized access to sensitive source code, deployment pipelines, and production infrastructure.
Remediation
Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide for CVE-2026-23658 and apply all recommended security updates or configuration changes provided by Microsoft.
Proactive Monitoring: Monitor Azure DevOps access logs for unusual authentication patterns, unauthorized administrative activities, or unexpected privilege changes among user accounts.
Compensating Controls: Implement strict network segmentation and ensure that access to Azure DevOps instances is restricted to known, trusted IP ranges via conditional access policies to limit the exposure of the management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations utilizing Microsoft Azure DevOps must prioritize the investigation of this vulnerability within their environment. While a specific patch version is not explicitly detailed in the provided metadata, administrators should immediately consult the Microsoft update guide to identify the required version to remediate this high-severity credential exposure.
More Microsoft CVEs
Sources
- Azure DevOps: msazure Elevation of Privilege Vulnerability Vendor advisory