July 31, 2023, 11:49 a.m. | Evan Grant

Tenable Research Advisories www.tenable.com

Unauthorized Access to Cross-Tenant Applications in a Microsoft Azure Service

A researcher at Tenable has discovered an issue that enables limited, unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets).


Tenable is continuing to work with Microsoft to coordinate the disclosure process, and will update this advisory with more details by 28 September 2023.



Evan Grant
Mon, 07/31/2023 - 07:49

access applications authentication azure azure service data disclosure issue microsoft microsoft azure process researcher secrets sensitive data service tenable unauthorized access work

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC