Microsoft Azure MCP Server Missing Authentication Vulnerability Allowing Information Disclosure

Vulnerability

A vulnerability exists in Azure MCP Server due to missing authentication for a critical function, enabling unauthorized attackers to disclose information over the network. This issue affects all versions of Azure MCP Server.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure over the network.

Added: Apr 3, 2026, 12:19 AM
Updated: Apr 3, 2026, 12:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
5.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.