Microsoft Rejects Critical Azure Vulnerability Report
A researcher reported a critical privilege-escalation flaw in Azure Backup for AKS. Users with only the low-privileged “Backup Contributor” role on a backup vault could gain full cluster-admin access and steal cluster secrets without needing Kubernetes credentials.
Microsoft rejected the submission and called the behavior expected. The researcher documented steps showing the escalation and later observed tightened access controls (silent fix). Affects Azure Kubernetes Service users who enable Backup for their clusters.
No CVE was issued.
