CVE-2026-35425
Microsoft · Azure API Management (APIM)
Improper access control in Microsoft Azure API Management allows an authenticated attacker to execute code over a network.
Executive summary
Microsoft Azure API Management contains an access control vulnerability that permits authorized attackers with high privileges to execute arbitrary code.
Vulnerability
This is an improper access control vulnerability that allows an authenticated attacker possessing high privileges to execute code over a network. The vulnerability leverages flaws in the management layer of the service to achieve unauthorized command execution.
Business impact
The vulnerability carries a CVSS score of 8.0, reflecting the high impact of remote code execution. Successful exploitation could lead to full compromise of the API management layer, exposing sensitive API keys, backend service configurations, and potentially allowing the attacker to intercept or modify traffic across the managed APIs.
Remediation
Immediate Action: Microsoft manages the underlying infrastructure for Azure APIM; review the Microsoft Security Response Center update guide to confirm if any user-side configuration changes are required.
Proactive Monitoring: Review access logs for suspicious administrative activity or anomalous API management service calls that deviate from standard operational patterns.
Compensating Controls: Ensure that access to the management plane of Azure APIM is restricted to the minimum number of authorized administrators using Multi-Factor Authentication (MFA).
Exploitation status
Public Exploit Available: No
Analyst recommendation
While Microsoft handles the remediation for this cloud service, administrators should ensure that their own administrative access controls remain robust. Monitor for any unusual activity in the APIM management console and apply any recommended updates provided by the vendor.