July 31, 2023, 11:49 a.m. | Evan Grant

Tenable Research Advisories www.tenable.com

Unauthorized Access to Cross-Tenant Applications in a Microsoft Azure Service

A researcher at Tenable has discovered an issue that enables limited, unauthorized access to cross-tenant applications and sensitive data (including but not limited to authentication secrets).


Tenable is continuing to work with Microsoft to coordinate the disclosure process, and will update this advisory with more details by 28 September 2023.



Evan Grant
Mon, 07/31/2023 - 07:49

access applications authentication azure azure service data disclosure issue microsoft microsoft azure process researcher secrets sensitive data service tenable unauthorized access work

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Senior Security Architect - Northwest region (Remote)

@ GuidePoint Security LLC | Remote

Senior Consultant, Cyber Security Architecture

@ 6point6 | Manchester, United Kingdom

Junior Security Architect

@ IQ-EQ | Port Louis, Mauritius

Senior Detection & Response Engineer

@ Expel | Remote

Cyber Security Systems Engineer ISSE Splunk

@ SAP | Southbank (Melbourne), VIC, AU, 3006