Skip to content

[Contribution] Cross-tenant Event Grid Privilege Escalation Vulnerability #436

@korniko98

Description

@korniko98

Summary (give a brief description of the issue)

"an Azure Event Grid System Topic vulnerability allowing us to view Event Subscriptions data for all tenants that had an Event Subscription configured due to a flaw in the filtering mechanism Microsoft used for displaying data to their customers. This vulnerability was disclosed through Microsoft Security Response Center as ‘VULN-162828’ which was classified as ‘Critical’ under the ‘Elevation of Privilege’ topic and later disclosed as ‘CVE-2025-59273’."

References (provide links to blogposts, etc.)

https://thecollective.eu/cross-tenant-event-grid-privilege-escalation-vulnerability/

Metadata

Metadata

Assignees

No one assigned

    Labels

    additionNew security issue or vulnerabilityazureIssue related to an Azure service

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions