Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability allows a standard administrator in one tenant to bypass security controls and affect resources across all tenants. This could enable unauthorized data modification, deletion, or creation within any tenant, impacting the integrity and availability of services. The main concern is confirming relevance and exposure due to the potential for widespread impact.
- Admins can access other tenants' data.
- Matters for trust and data protection.
- Verify if your systems are affected.
Attack Path
How an attacker could exploit the issue
An attacker with administrative privileges in one tenant could exploit a flaw in how the system checks permissions. By manipulating a request, an attacker could trick the system into performing actions, such as deleting or modifying resources, on tenants they should not have access to, potentially impacting data integrity and availability across the entire platform.
- Requires admin access in one tenant.
- Triggered by a crafted request.
- Risk of unauthorized resource modification.
Live Threat
Current exploitation, exposure, and threat context
A non-global administrator in one tenant could potentially affect resources in any other tenant. This may occur when the system fails to properly validate requests, allowing an administrator to perform actions across tenant boundaries by exploiting a discrepancy between how identity is checked and what actions are permitted.
- Resources across tenants could be affected.
- Actions could bypass tenant isolation.
- Unauthorized resource modification or deletion.
Operational Fix
Recommended remediation, mitigation, and detection steps
A critical vulnerability allows non-global administrators to bypass tenant restrictions and manipulate resources across any tenant. This threat requires immediate attention from platform and security teams responsible for identity and access management. The first practical step is to identify all instances of the affected technology, determine their reachability and business criticality, and confirm the accountable owner for each. Remediation planning should then be prioritized based on the identified risks.
- Platform and security teams own this.
- Verify affected technology and exposure.
- Plan targeted remediation based on risk.