Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Tenant Signup Bypass via Host Header Manipulation in Azure API Management |
Mon, 03 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Tenant Signup Bypass in Azure API Management via Host Header Manipulation |
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft azure Api Management |
|
| Vendors & Products |
Microsoft
Microsoft azure Api Management |
Thu, 30 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Tenant Signup Bypass in Azure API Management via Host Header Manipulation |
Wed, 22 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 21 Jul 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header). NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). NOTE: The supplier evaluated this report and determined that it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-22T15:47:05.047Z
Reserved: 2025-11-28T00:00:00.000Z
Link: CVE-2025-66390
Updated: 2026-07-22T15:19:03.139Z
Status : Awaiting Analysis
Published: 2026-07-21T14:16:32.797
Modified: 2026-07-23T18:28:35.280
Link: CVE-2025-66390
No data.
OpenCVE Enrichment
Updated: 2026-08-04T06:00:05Z