Security researchers have discovered two new ″Confused Deputy″ vulnerabilities affecting Microsoft Azure and Google Cloud Platform (GCP). The flaws could allow attackers to misuse trusted cloud services and gain higher privileges than they should normally have. The findings were reported by independent security researcher Justin O’Leary.

A Confused Deputy vulnerability happens when a trusted cloud service accepts a request without properly checking where it originally came from. Because of this missing verification, an attacker can trick the service into performing actions using its own higher privileges. This allows security controls to be bypassed without directly attacking the protected resource.
According to the researcher, the Microsoft Azure issue involved the Azure Kubernetes Service (AKS) backup feature. An attacker with Backup Contributor permissions could reportedly escalate their privileges and gain cluster administrator access. With this level of control, they could potentially manage workloads, access sensitive information, and make major changes inside the Kubernetes environment.

The Google Cloud vulnerability affected its managed identity trust process. The flaw could allow attackers to misuse trusted identity relationships and gain access that should normally be restricted. By abusing the trust chain, attackers may be able to perform unauthorized actions while appearing to be legitimate cloud services.
Justin O’Leary said he responsibly disclosed both vulnerabilities to Microsoft and Google earlier this year. According to his findings, neither company officially acknowledged the reported issues or awarded a bug bounty. However, Microsoft appears to have quietly fixed the Azure vulnerability without publicly announcing the security update.

The term “Confused Deputy” is not new in cybersecurity. It was first introduced by computer scientist Norm Hardy in 1988 after he identified a similar security design problem years earlier. Even after decades of improvements in identity and access management, experts say these vulnerabilities continue to appear because modern cloud systems have become increasingly large and complex.
Researchers believe these flaws often remain hidden because many cloud services rely on reusable infrastructure and automated trust relationships. If developers fail to preserve the original source of a request, attackers can exploit the trusted service instead of attacking the target directly. This makes the vulnerability difficult to detect using traditional security methods.

The discovery highlights the importance of carefully validating identity requests and maintaining strong access controls across cloud platforms. Organizations using Microsoft Azure and Google Cloud should regularly review privileged identities, service permissions, and trust relationships to reduce the risk of privilege escalation attacks. The research serves as another reminder that cloud security depends not only on authentication but also on preserving trust throughout every request.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news