<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod" -->

---
title: &#x27;Confused Deputy&#x27; Flaws Persist in Google Cloud,...
description: Independent security researcher Justin O&#x27;Leary discovered two &#x27;confused deputy&#x27; vulnerabilities in Microsoft Azure and Google Cloud Platform (GCP). The Azure...
canonical: https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: &#x27;Confused Deputy&#x27; Flaws Persist in Google Cloud, Microsoft Azure | daily.dev
og:description: Independent security researcher Justin O&#x27;Leary discovered two &#x27;confused deputy&#x27; vulnerabilities in Microsoft Azure and Google Cloud Platform (GCP). The Azure...
og:url: https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod
og:image: https://api.daily.dev/og/posts/zJv88PGOd.png
og:image:alt: &#x27;Confused Deputy&#x27; Flaws Persist in Google Cloud, Microsoft Azure
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure

**[Dark Reading](https://daily.dev/sources/dr)** · 6 min read · 1 upvotes · 0 comments

## Summary

Independent security researcher Justin O'Leary discovered two 'confused deputy' vulnerabilities in Microsoft Azure and Google Cloud Platform (GCP). The Azure flaw affects the AKS backup service, allowing an attacker to escalate from Backup Contributor to cluster-admin privileges, enabling data exfiltration or malicious workload deployment. The GCP flaw involves Config Connector, an open source Kubernetes add-on that skips IAM authorization checks, letting a user with basic Kubernetes namespace access become a GCP Organization Owner — with the attack logged only as service account activity, making the attacker invisible in audit logs. Microsoft appears to have silently patched its flaw without acknowledgment, while Google's VRP panel declined to classify the GCP issue as a vulnerability. O'Leary argues both cases reflect systemic weaknesses in how cloud providers build managed identity trust chains, and will present full details at Black Hat USA 2026.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure>

## Questions this post answers

### What is the confused deputy vulnerability found in Azure Kubernetes Service's backup feature?

A confused deputy flaw in Azure Kubernetes Service's Trusted Access backup feature lets an attacker escalate from a basic Backup Contributor role, which has no Kubernetes permissions, to cluster-admin privileges on the AKS cluster. This allows exfiltrating sensitive data from backups or deploying malicious workloads to any cluster in the network. The flaw was disclosed on May 12 and appears to have been silently patched by Microsoft.

_Teams securing Kubernetes backup pipelines follow disclosures like this on daily.dev to catch privilege-escalation risks early._

### How does the Config Connector authorization bypass in Google Cloud work?

Google Cloud's Config Connector, an add-on for managing GCP resources via Kubernetes, fails to verify whether a user is authorized to grant IAM roles on a target organization before passing the request to GCP's API using its own elevated credentials. An attacker with only basic Kubernetes namespace access and no GCP permissions can use this to become GCP Organization Owner, and the attack is logged as service account activity, making the attacker invisible in cloud audit logs.

_Engineers hardening GCP IAM configurations track findings like this on daily.dev before attackers exploit the gap._

### Why didn't Google pay a bug bounty for the Config Connector vulnerability?

Google's Vulnerability Rewards Program panel initially signaled a bounty was likely but ultimately decided the Config Connector issue did not qualify as a vulnerability, arguing instead that customers are responsible for setting the connector's permissions correctly. The researcher who found it, Justin O'Leary, disputes this, noting Config Connector itself never verifies whether a user is authorized to request the permissions being granted.

_Security researchers weighing disclosure and bounty outcomes compare cases like this on daily.dev._

## Similar posts on daily.dev

- [Microsoft rejects critical Azure vulnerability report, no CVE issued](https://daily.dev/posts/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued-8pc6eifjz) · BleepingComputer · 0 upvotes · 0 comments
- [Google told researcher 'Nice catch\!' Then denied bug bounty for flaw it still hasn't fixed](https://daily.dev/posts/google-told-researcher-nice-catch-then-denied-bug-bounty-for-flaw-it-still-hasn-t-fixed-wirhwphqp) · The Register · 0 upvotes · 0 comments
- [7 GCP Misconfigurations That Are Actively Being Exploited in 2026](https://daily.dev/posts/7-gcp-misconfigurations-that-are-actively-being-exploited-in-2026-8gemotlze) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#azure](https://daily.dev/tags/azure), [#gcp](https://daily.dev/tags/gcp)

[View this post on daily.dev](https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure","url":"https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod"},"datePublished":"2026-07-27T21:18:19.239Z","dateModified":"2026-09-13T20:55:34.691Z","description":"Independent security researcher Justin O'Leary discovered two 'confused deputy' vulnerabilities in Microsoft Azure and Google Cloud Platform (GCP). The Azure...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/835e49e6eace0eeae26f4e77020d7a59?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/835e49e6eace0eeae26f4e77020d7a59?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,azure,gcp","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/confused-deputy-flaws-persist-in-google-cloud-microsoft-azure-zjv88pgod#faq","mainEntity":[{"@type":"Question","name":"What is the confused deputy vulnerability found in Azure Kubernetes Service's backup feature?","acceptedAnswer":{"@type":"Answer","text":"A confused deputy flaw in Azure Kubernetes Service's Trusted Access backup feature lets an attacker escalate from a basic Backup Contributor role, which has no Kubernetes permissions, to cluster-admin privileges on the AKS cluster. This allows exfiltrating sensitive data from backups or deploying malicious workloads to any cluster in the network. The flaw was disclosed on May 12 and appears to have been silently patched by Microsoft. Teams securing Kubernetes backup pipelines follow disclosures like this on daily.dev to catch privilege-escalation risks early."}},{"@type":"Question","name":"How does the Config Connector authorization bypass in Google Cloud work?","acceptedAnswer":{"@type":"Answer","text":"Google Cloud's Config Connector, an add-on for managing GCP resources via Kubernetes, fails to verify whether a user is authorized to grant IAM roles on a target organization before passing the request to GCP's API using its own elevated credentials. An attacker with only basic Kubernetes namespace access and no GCP permissions can use this to become GCP Organization Owner, and the attack is logged as service account activity, making the attacker invisible in cloud audit logs. Engineers hardening GCP IAM configurations track findings like this on daily.dev before attackers exploit the gap."}},{"@type":"Question","name":"Why didn't Google pay a bug bounty for the Config Connector vulnerability?","acceptedAnswer":{"@type":"Answer","text":"Google's Vulnerability Rewards Program panel initially signaled a bounty was likely but ultimately decided the Config Connector issue did not qualify as a vulnerability, arguing instead that customers are responsible for setting the connector's permissions correctly. The researcher who found it, Justin O'Leary, disputes this, noting Config Connector itself never verifies whether a user is authorized to request the permissions being granted. Security researchers weighing disclosure and bounty outcomes compare cases like this on daily.dev."}}]}
```

