'Confused Deputy' Vulnerabilities Found in Azure and Google Cloud
Want more insights like this?
Security researcher Justin O'Leary found serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform — disclosing the Azure bug on 12 May and the GCP one on 18 June — and neither company properly acknowledged them.
The Azure bug lets an attacker escalate from Backup Contributor, with zero Kubernetes permissions, to full cluster-admin access via the AKS backup service. O'Leary rates it CVSS 9.9. The GCP flaw sits in Config Connector, the open source Kubernetes add-on for managing GCP resources, and lets someone with basic namespace access silently crown themselves GCP Organization Owner — with the attack hidden from audit logs, since it looks like service account activity.
Microsoft appears to have quietly patched its flaw without disclosure or a CVE. Google's bug bounty panel told O'Leary the report "didn't qualify," arguing customers are responsible for their own permission settings, though it said it might fix the issue anyway. Anyone running Config Connector should review who holds namespace access in the meantime.
O'Leary details both at Black Hat USA 2026, in a talk called "Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains."
Source: Dark Reading