CVE-2026-48567 is a CVSS 10.0 authentication bypass in Azure HorizonDB — Microsoft’s cloud-native distributed database service. Published June 4, 2026, it requires no credentials, no user interaction, and can be exploited over the network. The outcome is full privilege escalation to the target database instance.

Ten Intigriti programs have Azure infrastructure in scope, with bounty ceilings ranging from €15k to €100k.

What Azure HorizonDB is

HorizonDB is Microsoft’s managed distributed database service, positioned as an alternative to Cosmos DB for workloads that need strong consistency at global scale. It exposes REST and gRPC APIs for data operations, with Azure Active Directory (Entra ID) as the default authentication layer.

Like most Azure PaaS services, HorizonDB relies on bearer tokens issued by Entra ID. Clients authenticate once, receive a token, and include it in subsequent requests. The service validates the token signature and claims — or is supposed to.

How the bypass works

CVE-2026-48567 is classified as “authentication bypass by spoofing,” which in practice covers a few distinct attack shapes. Based on the CVSS vector (Network/None/None/Changed) and the authentication-bypass-by-spoofing CWE, the most likely mechanism is identity token manipulation rather than a simple credential skip.

The attack pattern here follows a familiar path in cloud APIs:

Token claim injection. Some REST APIs accept JWTs from multiple sources (client-provided headers, forwarded headers from proxies, service-to-service tokens) without strictly pinning which source takes precedence. An attacker who can inject or override the X-Identity-Token or similar header with a crafted token — one whose signature is never validated against Entra ID — can substitute their claimed identity.

SSRF-assisted token theft. Cloud services often use the instance metadata endpoint (IMDS) to fetch their own credentials. If HorizonDB has an SSRF surface (file import, webhook, or URL fetch), an attacker can redirect a request to http://169.254.169.254/metadata/identity/oauth2/token and capture a valid bearer token for the service identity, then replay it with elevated claims.

Header precedence abuse. When a service sits behind a load balancer or API gateway, double-submitting authentication headers (one from a legitimate proxy, one attacker-controlled) can exploit ambiguous precedence logic — the backend reads the attacker’s header while the gateway validates a different one.

The CVE score tells you what matters: CVSS 10.0, scope changed, confidentiality/integrity/availability all HIGH. Whatever the exact mechanism, the result is full compromise of the targeted HorizonDB instance.

Why this scores a 10.0

The CVSS 10.0 breaks down like this:

  • Attack vector: Network — exploitable remotely, no local access needed
  • Attack complexity: Low — no race conditions, no target-specific knowledge required
  • Privileges required: None — attacker starts with zero authentication
  • User interaction: None — fully automated, no victim needs to click anything
  • Scope: Changed — the vulnerability extends impact beyond the database itself (think storage, connected services, downstream Azure resources)
  • Confidentiality/Integrity/Availability: High/High/High — full triad compromise

“Scope changed” is the detail that pushes this from 9.8 to 10.0. It means a successful attack doesn’t stay contained to HorizonDB; it can pivot into connected Azure resources using the service identity.

Programs with this in scope

Ten Intigriti programs currently have Azure infrastructure in scope. Before testing anything, read each program’s cloud infrastructure testing rules — most require you to notify before touching cloud APIs and prohibit automated scanning without approval.

ProgramMax bountyNotes
Intel€100,000Large cloud scope
Capture Our Flag€51,000Dedicated cloud infra
Altera€30,000Intel subsidiary
Arm€20,000Check specific Azure scope
Trusted Firmware€20,000Embedded + cloud
BMW Group Automotive€15,000Production cloud
Capital.com€15,000Fintech, strict rules
Delen Private Bank€15,000Read cloud testing policy carefully
Yahoo Bug Bounty€15,000Confirm HorizonDB in scope
Dropbox Bug Bounty€15,000Check asset list

The Intel program at €100k ceiling is the obvious target, but also the most scrutinized. Smaller programs sometimes accept more straightforward cloud reports without as much friction.

What to test

Cloud authentication bypass testing is different from standard web app hunting. You’re not looking for a login form to bypass — you’re looking for gaps in how the service validates token provenance.

Reconnaissance first:

# Check if target runs HorizonDB via DNS/service discovery
# Look for Azure-specific headers in API responses
curl -I https://target.example.com/api/ | grep -i 'x-ms\|x-azure'

# Check for exposed management endpoints
curl https://target.example.com/.well-known/openid-configuration

Token handling:

# Test missing Authorization header — does the endpoint respond with data or 401?
curl -s https://api.target.example.com/v1/data/items

# Test malformed token — does the server validate the signature?
curl -H "Authorization: Bearer eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiJ9." \
  https://api.target.example.com/v1/data/items

Header injection checks:

# Test if X-Forwarded-User or similar headers bypass token validation
curl -H "X-Forwarded-User: admin" \
     -H "X-Identity-Token: [crafted]" \
     https://api.target.example.com/v1/admin

SSRF surface:

# If the service has any URL fetch or file import functionality, test for IMDS access
# Use a controlled server (Burp Collaborator, interactsh) to confirm SSRF first

Stop at version/endpoint confirmation if the program’s rules don’t permit deeper testing. A well-documented report showing the endpoint accepts unsigned tokens is enough for a critical finding.

Remediation

Microsoft’s fix is in the June 2026 Patch Tuesday release. For teams running HorizonDB instances:

  1. Apply the June 2026 security update via Azure portal or az CLI
  2. Audit API gateway configurations — ensure no proxy headers can override Entra ID token validation
  3. Review service-to-service authentication: confirm token exchange flows validate signatures, not just presence
  4. Enable Azure Defender for HorizonDB alerts on authentication anomalies
  5. Check access logs for requests with malformed or missing tokens that returned 200 responses before the patch

Managed HorizonDB instances (Azure-hosted) are patched automatically. Self-managed or containerized deployments need manual action.

References

For broader CVE triage and prioritization workflows, the CVE opportunity analysis for June 2026 shows how to evaluate new disclosures against active bug bounty targets. The CVE intelligence tools guide covers the tooling stack for staying ahead of new auth bypass CVEs like this one.