LiveActive security incident?Get immediate response
CVE Record

CVE-2025-66390: In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Aut...

In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI level. In other words, disabling signup in the UI does not disable the underlying API endpoint (which still accepts cross-tenant requests based on the Host header). NOTE: The supplier states that they evaluated the report and determined it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation). NOTE: The supplier evaluated this report and determined that it did not cross a security boundary (i.e., the observed behavior was a configuration/state issue rather than an exploitable product vulnerability affecting tenant isolation).

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This report describes an Azure API Management signup-control bypass where a disabled UI setting may not stop the underlying registration endpoint. The claimed impact is unauthorized self-service account registration in another tenant context. Microsoft reportedly assessed it as not crossing a security boundary, so business urgency depends on whether public signup is enabled and how portal accounts are governed.

Executive priority

Prioritize review for internet-facing APIM developer portals that allow self-service accounts. This is not KEV-listed and is vendor-disputed, but unwanted registration paths can create governance, data-access, or API-subscription risk if portal onboarding grants meaningful privileges.

Technical view

The CVE alleges that APIM self-service signup using username/password Basic Authentication remains reachable through backend registration flow manipulation involving hostname or tenant identifier changes. CVSS is listed as 9.8, CWE-284. The supplier note says the behavior was treated as configuration or state handling, not an exploitable tenant-isolation vulnerability.

Likely exposure

Exposure appears limited to Azure API Management instances using the developer portal self-service signup flow, especially username/password Basic Authentication. The source bundle does not identify specific CPEs, versions, patches, or affected product listings beyond Azure API Management through 2025-10-17.

Exploitation context

No active exploitation is cited, and CISA KEV status is false. Public GitHub references exist, but the bundle also records Microsoft’s position that no security boundary was crossed. Treat this as a configuration and access-control review item unless stronger vendor or incident evidence emerges.

Researcher notes

The key uncertainty is impact. The CVE text claims a cross-tenant signup bypass, while the supplier says it did not cross a security boundary. Avoid assuming tenant data access or isolation compromise without additional evidence. Validate control behavior in owned tenants only and track vendor advisories.

Mitigation direction

  • Review Azure API Management developer portal signup settings.
  • Disable username/password self-service signup where not required.
  • Check Microsoft Azure API Management guidance for official remediation.
  • Restrict developer portal account approval and permissions.
  • Monitor new portal registrations for unexpected tenants or domains.

Validation and detection

  • Inventory APIM instances with developer portals enabled.
  • Confirm whether Basic Authentication self-service signup is enabled.
  • Review recent developer portal account creation events.
  • Verify disabled signup cannot create usable accounts.
  • Document Microsoft guidance and any compensating controls.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-66390 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
3Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2025-66390Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.