CVE-2025-29813 is a critical authentication bypass vulnerability in Microsoft Azure DevOps, allowing an unauthenticated attacker to achieve full privilege escalation over a network. With a CVSS score of 9.8, this flaw presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability without user interaction. While not yet listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness. Currently, no public exploit code is available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_devops:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.