# CHQ-ED-2026-017

- **Artifact ID:** CHQ-ED-2026-017
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-017
- **Machine-record SHA-256:** `47deb09815ce35691d5a1d55b99c8aa8cc01197769da581c419c514c09bb497f`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-017",
  "associated_position": "CHQ-P-2026-014 v1.0",
  "relationship": "reinforcement",
  "issuance_date": "2026-05-04",
  "evidence_freeze_time": "2026-05-04T00:00:00Z",
  "total_exhibits": 2,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "Core Position",
      "claim_text": "A management plane role exercised effective authority over identity primitives that the role’s documented scope did not declare, with the gap producing service principal takeover capability across the entire tenant from a role presented to operators as low-privilege.",
      "evidence_exhibits": [
        "CHQ-EX-2026-019"
      ],
      "relevant_sections": "I. Factual Record — Mechanism, Population Exposure",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-04-29-02: Microsoft Entra Agent ID Administrator Scope Overreach — The Agent ID Administrator role, scoped in documentation to AI agent identity management, exercised ownership transfer authority over arbitrary non-agent service principals. A holder could take ownership of any service principal, add credentials, and authenticate as that principal — full takeover. The administrative interface displayed no privileged-role indicator."
    },
    {
      "claim_id": "C-02",
      "position_section": "Core Position",
      "claim_text": "An AI gateway with credential aggregation across multiple upstream providers exercised effective authority over the entire connected provider portfolio, with compromise of the gateway’s authentication path producing a credential blast radius operationally equivalent to compromise of every connected account.",
      "evidence_exhibits": [
        "CHQ-EX-2026-016"
      ],
      "relevant_sections": "I. Factual Record — Targeted Data, Outcome",
      "verification_type": "PRIMARY",
      "evidence_class": "PRIMARY",
      "source_text": "SN-2026-05-01-01: LiteLLM CVE-2026-42208 — The LiteLLM proxy stored credentials for 100+ LLM providers in a centralized database. Pre-authentication SQL injection in the API key verification path enabled enumeration of three credential tables. The deployment context placed credential aggregation in infrastructure not classified as privileged."
    },
    {
      "claim_id": "C-03",
      "position_section": "Evidence Pattern",
      "claim_text": "Across the documented signals, the management plane component exercised effective authority over identity, credential, or service-principal infrastructure through paths that the standard identity enforcement model did not govern.",
      "evidence_exhibits": [
        "CHQ-EX-2026-019",
        "CHQ-EX-2026-016"
      ],
      "relevant_sections": "II. Failure Pattern",
      "verification_type": "PATTERN",
      "evidence_class": "PATTERN",
      "source_text": "Pattern across SN-2026-04-29-02 and SN-2026-05-01-01. The management plane is structurally upstream of the identity enforcement boundary. Authority granted at the management layer is exercised through identity primitives the management layer composes. Identity-layer monitoring sees the resulting authorized actions, not the unauthorized authority composition that produced them."
    }
  ],
  "signals": [
    {
      "signal_id": "SN-2026-04-29-02",
      "signal_type": "VENDOR_DISCLOSURE",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-019"
      ]
    },
    {
      "signal_id": "SN-2026-05-01-01",
      "signal_type": "INCIDENT_REPORT",
      "classification": "PRIMARY",
      "evidence_exhibits": [
        "CHQ-EX-2026-016"
      ]
    }
  ],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-016",
      "title": "LiteLLM CVE-2026-42208: AI Gateway Pre-Authentication Credential Extraction",
      "temporal_tag": "OPERATIONAL (APRIL 24–26, 2026)"
    },
    {
      "id": "CHQ-EX-2026-019",
      "title": "Microsoft Entra Agent ID Administrator Scope Overreach",
      "temporal_tag": "OPERATIONAL (MARCH 1 – APRIL 23, 2026)"
    }
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-014 v1.0.",
    "Primary signals: SN-2026-04-29-02 (Entra Agent ID) carries CONFIRMED status — Silverfort independent research, Microsoft Security Response Center confirmation of the issue, patch deployment confirmed across all cloud environments. SN-2026-05-01-01 (LiteLLM) carries CONFIRMED status — Sysdig telemetry confirmed exploitation, LiteLLM published advisory, Belgium CCB issued advisory.",
    "The two signals demonstrate the same structural condition through distinct mechanisms: governance-layer scope overreach in Entra and aggregation-layer credential exposure in LiteLLM. Failure mode independence is high. Both reinforce that management plane authority operates outside identity enforcement at the point of execution.",
    "CCD record — two layers decomposed (governance composition, credential aggregation), both CONFIRMED. CCD_INTEGRITY: STRONG. ALIGNMENT_PRESSURE: HIGH.",
    "Primary signals compiled from CHQ Classification Log. All signals passed TSEM evaluation. Source independence assessed per CCD enforcement protocol.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-017 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-014 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
