Microsoft disclosed a critical missing-authorization flaw (CVSS 9.9) in Azure SRE Agent, an autonomous AI-powered service that monitors, diagnoses, and remediates issues in Azure-hosted infrastructure. The bug broke the agent’s on-behalf-of privilege elevation flow, which could have let a low-privileged remote attacker with no user interaction inherit the agent’s managed-identity permissions and reach resources beyond its intended security boundary. Microsoft fully mitigated the issue at the cloud service level; no proof-of-concept exploit was published and no customer action was required.