'Confused Deputy' Vulnerabilities Found in Azure and Google Cloud — Neither Company Acknowledged Them
Explore serious security flaws in Microsoft Azure and Google Cloud, and learn about their impact on Kubernetes access control.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo