Azure AKS Backup Privilege Flaw: Silent Patch Suspected, No CVE Issued

TL;DR
Security researcher Justin O'Leary alleges a critical privilege-escalation flaw in Azure Backup for AKS could let a low-privileged user become cluster-admin via Trusted Access; Microsoft rejected the report as expected behavior with no product changes and blocked CVE issuance, while CERT/CC independently validated the bug and assigned VU#284781. After disclosure, Microsoft reportedly changed behavior and added permission checks, suggesting a silent patch; no public advisory or CVE was issued, leaving defenders with limited visibility into exposure and remediation timelines.
Microsoft rejects critical Azure vulnerability report, no CVE issued BleepingComputer
Want the full story? Read the original reporting
Read on BleepingComputer