Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Azure-APIM-Cross-Tenant-Signup-Bypass — Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice - closed as "by design". | Kitploit
Tools/GitHubGitHub/bountyyfi/azure-apim-cross-tenant-signup-bypass
ReconnaissanceVulnerability AnalysisWeb Application ExploitationInformation GatheringCloud SecurityMisconfigurationAPI Security
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
bountyyfi/azure-apim-cross-tenant-signup-bypass

Azure-APIM-Cross-Tenant-Signup-Bypass

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice - closed as "by design".

View Repository
16242 months agoNot yet reviewed

Azure APIM Cross-Tenant Signup Bypass

Status (01.12.2025): This vulnerability is still live and exploitable. Microsoft has not patched this issue and considers it "by design."

Security Advisory

GHSA-vcwf-73jp-r7mv

CVE-2025-66390

Summary

A security vulnerability in Azure API Management (APIM) Developer Portal allows attackers to register accounts on any APIM instance that has Basic Authentication enabled, even when administrators have disabled user signup in the portal UI.

This bypass enables cross-tenant account creation, potentially allowing unauthorized access to API documentation, subscription keys, and other resources exposed through the Developer Portal.

Disclosure Timeline

DateAction
2025-09-30Vulnerability discovered
2025-09-30Initial report submitted to MSRC
2025-10-30MSRC response: Closed as "not a vulnerability"
2025-11-01Second report submitted to MSRC with additional details
2025-11-20MSRC response: Closed as "by design"
2025-11-20Reported to CERT-FI
2025-11-26Public disclosure
2025-11-27CVE requested from MITRE
2026-07-09CVE-2025-66390 assigned by MITRE TL-Root/CNA-LR

Vulnerability Details

The Issue

When Azure APIM is configured with Basic Authentication for the Developer Portal, administrators can disable user registration through the Azure Portal UI. However, this only hides the signup form in the portal interface.

The underlying signup API endpoint remains active and accepts registration requests directly, bypassing the UI restriction entirely.

Root Cause

Two issues combine to create this vulnerability:

  1. UI-only restriction: Disabling signup only hides the form in the portal UI. The backend signup API remains active and accessible.
  2. No tenant validation: The signup API does not validate that the request originates from the same tenant’s portal. Requests can be crafted from any source to register on any vulnerable instance.

Attack Vector

The attack requires two APIM instances:

  1. Attacker’s instance: Any APIM Developer Portal with signup enabled (or attacker’s own APIM instance)
  2. Target instance: Victim’s APIM Developer Portal with signup “disabled” in UI but Basic Authentication still configured

Steps:

  1. Attacker accesses their own APIM Developer Portal signup page (where signup is enabled)
  2. Attacker fills in the signup form and intercepts the request (e.g., using Burp Suite)
  3. Attacker changes the Host header from their instance to the target instance
  4. Attacker submits the modified request
  5. Account is created on the target instance despite signup being “disabled” in their admin console
  6. Attacker gains access to the target Developer Portal as a registered user

Key technical detail: The cross-tenant bypass works by manipulating the Host header in the signup POST request. The /signup endpoint processes requests based on the Host header without validating tenant boundaries.

Example request manipulation:

POST /signup HTTP/1.1
Host: target-apim.developer.azure-api.net   <-- Changed from attacker's instance
Origin: https://attacker-apim.developer.azure-api.net
Content-Type: application/json

{"challenge":{...},"signupData":{"email":"[email protected]",...}}

The core issue: disabling signup in the UI does not disable the underlying API. The API endpoint accepts cross-tenant requests based on the Host header.

Impact

  • Cross-tenant account creation - register on any APIM instance with Basic Auth enabled
  • Bypass of administrative controls - signup restrictions are ineffective
  • Access to API documentation that may contain sensitive internal information
  • Potential to request API subscription keys depending on portal configuration
  • Internal portal exposure - external attackers can register on “internal” portals

Affected Configurations

Your APIM instance is vulnerable if:

  • Basic Authentication identity provider is configured (even if signup is “disabled” in UI)
  • The Developer Portal is deployed and accessible

Your APIM instance is NOT vulnerable if:

  • Basic Authentication identity provider is completely removed (not just signup disabled)
  • Only Azure AD / OAuth authentication is configured
  • Developer Portal is not deployed or is disabled

Key point: Disabling signup in the Azure Portal UI is NOT sufficient. The Basic Authentication identity provider must be completely removed to prevent cross-tenant signup bypass.

Azure Resource Properties

Use these property values to identify vulnerable APIM instances via Azure Resource Graph, ARM templates, or Azure Policy.

Vulnerable Configuration Properties

Property PathVulnerable ValueDescription
properties.developerPortalStatusEnabledDeveloper Portal is accessible
sku.nameDeveloper, Basic, Standard, PremiumNon-Consumption tiers (Consumption tier has limited portal features)

Identity Provider Check (Sub-resource)

The Basic Authentication identity provider is a separate resource under the APIM instance:

Resource Type: Microsoft.ApiManagement/service/identityProviders
Name: basic

Vulnerable if exists: The presence of a basic identity provider resource indicates Basic Authentication is configured.

Portal Signup Settings (Sub-resource)

Resource Type: Microsoft.ApiManagement/service/portalsettings/signup
Property: properties.enabled
PropertyValueMeaning
properties.enabledtrueSignup visible in UI
properties.enabledfalseSignup hidden in UI (API still works if Basic Auth exists!)

Azure Resource Graph Query

Use this query to find potentially vulnerable APIM instances:

resources
| where type == "microsoft.apimanagement/service"
| where properties.developerPortalStatus == "Enabled"
| where sku.name != "Consumption"
| project name, resourceGroup, subscriptionId, location, sku.name, properties.developerPortalStatus

To check for Basic Auth identity providers:

resources
| where type == "microsoft.apimanagement/service/identityproviders"
| where name endswith "/basic"
| project apimInstance=tostring(split(id, "/providers/Microsoft.ApiManagement/service/")[1]), resourceGroup, subscriptionId

Azure CLI Commands

Check Developer Portal status:

az apim show --name <apim-name> --resource-group <rg-name> --query "{name:name, portalStatus:developerPortalStatus, sku:sku.name}"

List identity providers (check for 'basic'):

az apim identity-provider list --resource-group <rg-name> --service-name <apim-name> --query "[].name"

Check signup settings:

az rest --method get --url "https://management.azure.com/subscriptions/<sub-id>/resourceGroups/<rg-name>/providers/Microsoft.ApiManagement/service/<apim-name>/portalsettings/signup?api-version=2022-08-01" --query "properties.enabled"

Summary Table

ConditionProperty/ResourceVulnerable Value
Portal enabledproperties.developerPortalStatus== 'Enabled'
Non-Consumption SKUsku.name!= 'Consumption'
Basic Auth existsidentityProviders/basic resourceResource exists
Signup hidden (bypass possible)portalsettings/signup.properties.enabled== false (with Basic Auth)
Download Tool