<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

'Confused Deputy' Vulnerabilities Found in Azure and Google Cloud — Neither Company Acknowledged Them

Explore serious security flaws in Microsoft Azure and Google Cloud, and learn about their impact on Kubernetes access control.
Content Team

Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.

Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo