← Back to Feed

'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

July 27, 2026 · Dark Reading · Severity: LOW

Confused deputy vulnerabilities persist across major cloud platforms including Google Cloud and Microsoft Azure, enabling attackers to trick one cloud service into acting on behalf of the attacker and acquiring administrative credentials for another service. These cross-tenant confused deputy flaws exploit the trust relationships between cloud services and the way identity and access management tokens are passed between components, allowing adversaries to escalate privileges beyond their authorized scope. The recurring nature of these vulnerabilities across different platforms suggests a fundamental architectural challenge in cloud identity systems that has not been fully resolved.

Key Takeaways

  • Confused deputy vulnerabilities in Google Cloud and Azure allow attackers to acquire admin credentials across cloud services.
  • The flaws exploit cross-service trust relationships and token passing to escalate privileges beyond authorized scope.
  • The persistence of this class of vulnerability across multiple major platforms indicates a systemic architectural issue.
☕ Buy a Coffee