CVE-2026-35425

Microsoft · Azure API Management (APIM)

Improper access control in Microsoft Azure API Management allows an authenticated attacker to execute code over a network.

Executive summary

Microsoft Azure API Management contains an access control vulnerability that permits authorized attackers with high privileges to execute arbitrary code.

Vulnerability

This is an improper access control vulnerability that allows an authenticated attacker possessing high privileges to execute code over a network. The vulnerability leverages flaws in the management layer of the service to achieve unauthorized command execution.

Business impact

The vulnerability carries a CVSS score of 8.0, reflecting the high impact of remote code execution. Successful exploitation could lead to full compromise of the API management layer, exposing sensitive API keys, backend service configurations, and potentially allowing the attacker to intercept or modify traffic across the managed APIs.

Remediation

Immediate Action: Microsoft manages the underlying infrastructure for Azure APIM; review the Microsoft Security Response Center update guide to confirm if any user-side configuration changes are required.

Proactive Monitoring: Review access logs for suspicious administrative activity or anomalous API management service calls that deviate from standard operational patterns.

Compensating Controls: Ensure that access to the management plane of Azure APIM is restricted to the minimum number of authorized administrators using Multi-Factor Authentication (MFA).

Exploitation status

Public Exploit Available: No

Analyst recommendation

While Microsoft handles the remediation for this cloud service, administrators should ensure that their own administrative access controls remain robust. Monitor for any unusual activity in the APIM management console and apply any recommended updates provided by the vendor.