Security researcher Justin O'Leary alleged that Azure Backup for AKS contained a critical privilege-escalation path that let a user with only the Azure Backup Contributor role gain Kubernetes cluster-admin access on a target AKS cluster. The reported issue involved Azure Trusted Access, where enabling backup could configure the backup extension with elevated permissions that could then be abused to extract secrets, deploy malicious workloads, or otherwise take over the cluster. CERT/CC reportedly validated the finding and treated it as a legitimate vulnerability.
Microsoft rejected the report, said the behavior was expected and required pre-existing administrative privileges, and did not issue a CVE or public advisory. O'Leary said the original exploit path later stopped working and that new permission checks and manual Trusted Access configuration appeared in the service, which he characterized as a silent fix; Microsoft disputed that any product changes were made. The case also highlighted disclosure-governance concerns because Microsoft, acting as a CNA for its own products, retained final authority over CVE issuance after CERT/CC closed the case under CNA hierarchy rules, leaving defenders with limited public guidance on exposure and remediation for affected AKS environments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
After disclosure, O'Leary observed that the original attack path no longer worked and that Azure Backup for AKS appeared to add new permission checks and require manual Trusted Access configuration. The researcher characterized this as a silent fix, while Microsoft disputed that any product changes were made.
Microsoft said the reported behavior was expected and required pre-existing administrative privileges, so it did not issue a CVE or public advisory. Under CNA hierarchy rules, CERT/CC closed the case without assigning a CVE despite reportedly considering the issue valid.
Security researcher Justin O'Leary reported that users with only the Azure "Backup Contributor" role could allegedly abuse Azure Backup for AKS and Trusted Access to gain Kubernetes cluster-admin privileges on target AKS clusters.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcecybernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.