<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Rbac on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/rbac/</link><description>Recent content in Rbac on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 14:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/rbac/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-47633: Azure Cost Management Info Disclosure</title><link>https://zxcloudsecurity.co.uk/posts/azure-cost-management-information-disclosure-cve-2026-47633/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-cost-management-information-disclosure-cve-2026-47633/</guid><description>CVE-2026-47633 allows unauthenticated attackers to disclose sensitive data via Azure Cost Management. Learn the impact and mitigation steps.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47633">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in Microsoft Azure Cost Management allows an unauthenticated attacker to access sensitive financial or usage information over a network. The flaw exists within the Cost Management Interactive Experiences component and requires no user interaction or prior authentication to exploit. This is concerning as billing and cost data can expose details about an organisation&rsquo;s cloud resource footprint, spending patterns, and potentially sensitive infrastructure configurations.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review access controls and network exposure for Azure Cost Management portals and APIs; ensure Cost Management scopes are restricted to authorised identities via Azure RBAC and confirm that no public-facing Cost Management Interactive Experience endpoints are unnecessarily exposed while Microsoft&rsquo;s patch is applied.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47633">CVE-2026-47633 Microsoft Cost Management Information Disclosure Vulnerability</a></p>
]]></content:encoded></item></channel></rss>