Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.
Monitor for unexpected or unauthorized access attempts to API Connections. Review Azure Activity Logs for suspicious queries to the management.azure.com endpoint, especially those targeting the /extensions/proxy path.