critical · CVSS v3 10
CVE-2026-62874
CVE‑2026‑62874 exposes a flaw in Azure Billing where data authenticity is not properly verified. An attacker can exploit this to gain elevat
Overview
CVE‑2026‑62874 exposes a flaw in Azure Billing where data authenticity is not properly verified. An attacker can exploit this to gain elevated privileges on the network, potentially accessing or modifying billing and subscription data. The vulnerability is critical with a CVSS v3 score of 10.0.
Description
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
Impact
Defenders should be aware that an attacker could elevate privileges within the Azure environment, enabling unauthorized access to billing information, subscription controls, and potentially other network resources. This could lead to data exfiltration, unauthorized resource provisioning, or manipulation of cost data. The attack surface is limited to accounts with billing API access, but the impact on financial and operational integrity is significant.
Remediation
['Apply the latest Azure Billing security patch or update as released by Microsoft.', 'Restrict billing API permissions to the minimum required roles (e.g., Billing Reader or Billing Contributor) and enforce least‑privilege.', 'Enable Azure Multi‑Factor Authentication (MFA) for all accounts with billing or subscription management rights.', 'Configure Azure Policy to enforce that billing data is accessed only over authenticated and encrypted channels.', 'Monitor Azure Activity Logs for anomalous billing API calls and set up alerts for privilege escalation patterns.', 'Review and tighten network security groups and firewall rules to limit inbound traffic to billing endpoints.']
Risk context
The vulnerability is rated critical with a CVSS v3 score of 10.0, indicating a high likelihood of exploitation and severe impact. Although no EPSS data is available, the lack of data authenticity verification in a core Azure service warrants immediate attention and patching.
Affected products
- Microsoft Azure Billing
- Azure Subscription Management
- Azure Resource Manager
- Azure Cost Management
- Azure Advisor
- Azure Policy
- Azure Monitor
- Azure Security Center
Scores
- Severity
- critical
- CVSS v2
- 9.7
- CVSS v3
- 10
- CVSS v4
- —
- EPSS
- —