CVE-2025-29813 | Microsoft Azure DevOps Pipeline Job Token authentication bypass by assumed-immutable data
A vulnerability was found in Microsoft Azure DevOps. It has been classified as very critical. This affects an unknown part of the component Pipeline Job Token Handler. The manipulation leads to authentication bypass by assumed-immutable data.
This vulnerability is uniquely identified as CVE-2025-29813. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.