CVE-2025-66390: In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Aut...
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header). NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). NOTE: The supplier evaluated this report and determined that it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation).
Security readout for executives and security teams
Plain-English summary
This report describes an Azure API Management signup-control bypass where a disabled UI setting may not stop the underlying registration endpoint. The claimed impact is unauthorized self-service account registration in another tenant context. Microsoft reportedly assessed it as not crossing a security boundary, so business urgency depends on whether public signup is enabled and how portal accounts are governed.
Executive priority
Prioritize review for internet-facing APIM developer portals that allow self-service accounts. This is not KEV-listed and is vendor-disputed, but unwanted registration paths can create governance, data-access, or API-subscription risk if portal onboarding grants meaningful privileges.
Technical view
The CVE alleges that APIM self-service signup using username/password Basic Authentication remains reachable through backend registration flow manipulation involving hostname or tenant identifier changes. CVSS is listed as 9.8, CWE-284. The supplier note says the behavior was treated as configuration or state handling, not an exploitable tenant-isolation vulnerability.
Likely exposure
Exposure appears limited to Azure API Management instances using the developer portal self-service signup flow, especially username/password Basic Authentication. The source bundle does not identify specific CPEs, versions, patches, or affected product listings beyond Azure API Management through 2025-10-17.
Exploitation context
No active exploitation is cited, and CISA KEV status is false. Public GitHub references exist, but the bundle also records Microsoft’s position that no security boundary was crossed. Treat this as a configuration and access-control review item unless stronger vendor or incident evidence emerges.
Researcher notes
The key uncertainty is impact. The CVE text claims a cross-tenant signup bypass, while the supplier says it did not cross a security boundary. Avoid assuming tenant data access or isolation compromise without additional evidence. Validate control behavior in owned tenants only and track vendor advisories.
Mitigation direction
Review Azure API Management developer portal signup settings.
Disable username/password self-service signup where not required.
Check Microsoft Azure API Management guidance for official remediation.
Restrict developer portal account approval and permissions.
Monitor new portal registrations for unexpected tenants or domains.
Validation and detection
Inventory APIM instances with developer portals enabled.
Confirm whether Basic Authentication self-service signup is enabled.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-284: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-284 · source CWE mapping
Improper Access Control
Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.