CVE-2026-23658

8.6

Microsoft · Azure DevOps

Insufficiently protected credentials in Azure DevOps allow an unauthenticated remote attacker to perform unauthorized privilege escalation over a network.

Executive summary

A critical vulnerability in Microsoft Azure DevOps allows unauthenticated attackers to elevate privileges, posing a significant risk to organizational infrastructure.

Vulnerability

This vulnerability involves the insufficient protection of credentials, categorized under CWE-522, which permits an unauthenticated attacker to gain elevated privileges via a network vector.

Business impact

The ability for an unauthenticated user to escalate privileges represents a severe security failure that could lead to full administrative compromise of the DevOps environment. Given the CVSS score of 8.6, this flaw is categorized as High severity and threatens the integrity of software supply chains, potentially resulting in unauthorized access to sensitive source code, deployment pipelines, and production infrastructure.

Remediation

Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide for CVE-2026-23658 and apply all recommended security updates or configuration changes provided by Microsoft.

Proactive Monitoring: Monitor Azure DevOps access logs for unusual authentication patterns, unauthorized administrative activities, or unexpected privilege changes among user accounts.

Compensating Controls: Implement strict network segmentation and ensure that access to Azure DevOps instances is restricted to known, trusted IP ranges via conditional access policies to limit the exposure of the management interface.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing Microsoft Azure DevOps must prioritize the investigation of this vulnerability within their environment. While a specific patch version is not explicitly detailed in the provided metadata, administrators should immediately consult the Microsoft update guide to identify the required version to remediate this high-severity credential exposure.

More Microsoft CVEs

Sources