Researchers disclosed two severe flaws in Azure API Connections that exposed the trust model behind Microsoft’s managed connectors and could let attackers abuse authenticated connections to reach protected backend services. In the first issue, users with only Reader access to a connection could reportedly send authenticated requests through undocumented /extensions/proxy endpoints and inherit the connection’s existing privileges, exposing data from services including Azure Key Vault, Azure SQL, Jira, Slack, Salesforce, Azure Storage, Defender ATP, and Google services. The researcher also reported that the Jira connector could be abused for SSRF and API token theft when APIToken authentication was configured.
A second report alleged that Azure’s globally shared API Management architecture for connectors enabled cross-tenant compromise through Azure Resource Manager’s undocumented DynamicInvoke endpoint. By combining a custom connector with path traversal, an attacker could reportedly make privileged requests against arbitrary victims’ API Connections and potentially control or extract data from connected backends with inherited administrator-level access. The researcher said Microsoft confirmed the issue within days, deployed mitigations within a week, and later awarded a $40,000 bounty, although the published write-up warned the fix relied largely on blocking ../ and encoded variants and might be bypassable.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Binary Security published a detailed write-up alleging that Azure API Connections could be fully compromised across tenants via DynamicInvoke and path traversal against a globally shared APIM instance. The post said successful exploitation could expose or control connected backends including Azure Key Vault, Azure SQL, Jira, Salesforce, and Slack.
According to the researcher, MSRC confirmed the reported DynamicInvoke-based Azure API Connections vulnerability three days after submission. The flaw allegedly allowed privileged requests against other customers’ API Connections by abusing ARM request construction and path traversal.
A researcher reported a separate Azure API Connections vulnerability to MSRC involving the undocumented DynamicInvoke endpoint and path traversal through a custom connector. The issue allegedly enabled cross-tenant compromise of arbitrary victim API Connections on a shared API Management architecture.
The researcher states that Microsoft deployed mitigations within a week of the April 7 report. The implemented fix was described as a blacklist blocking ../ and some encoded variants in the attack path.
Binary Security publicly disclosed that undocumented Azure API Connections endpoints let users with Reader permissions proxy authenticated backend requests and access sensitive data. The write-up also described a Jira-specific SSRF and API token theft scenario when APIToken authentication was used.
Microsoft confirmed the Azure API Connection vulnerability that allowed Reader-level users to proxy authenticated GET requests to backend services through undocumented endpoints. The issue affected connected services such as Key Vault, SQL, Slack, Jira, Salesforce, and others.
Binary Security submitted reports to Microsoft covering the general Azure API Connections issue and a Jira-specific issue involving SSRF and API token theft. The reports described undocumented endpoints that let users abuse stored connection authentication to access backend services.
Microsoft fixed the API Connection vulnerability by restricting requests through /extensions/proxy, except for testrequests. The remediation was applied during the period from January 12 to January 17.
After the DynamicInvoke vulnerability report and mitigation, Microsoft later awarded the researcher a $40,000 bounty. The award was tied to the reported Azure API Connections cross-tenant compromise issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
binarysecurity.no
Open sourcelearn.microsoft.com
Open sourcebinarysecurity.no
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.