CVE-2026-70200
Microsoft · Azure Logic Apps
A path traversal vulnerability in Microsoft Azure Logic Apps enables unauthenticated remote attackers to elevate privileges.
Executive summary
A critical path traversal vulnerability in Microsoft Azure Logic Apps allows unauthenticated remote attackers to elevate their privileges within the environment.
Vulnerability
This vulnerability is caused by improper limitation of a pathname to a restricted directory (CWE-22) combined with improper authorization (CWE-285). By manipulating path parameters, an unauthenticated attacker can bypass restrictions and achieve unauthorized privilege elevation.
Business impact
With a CVSS score of 10.0, this vulnerability poses a severe risk to the integrity and confidentiality of workflows managed by Azure Logic Apps. An attacker could potentially access sensitive data or manipulate business logic flows, leading to unauthorized actions within the enterprise environment and significant operational disruption.
Remediation
Immediate Action: Consult the official Microsoft security advisory and apply all relevant security updates to your Logic Apps instances as they become available.
Proactive Monitoring: Monitor workflow execution logs for unexpected file path access or unauthorized attempts to modify application configuration files.
Compensating Controls: Enforce the principle of least privilege for all service identities associated with Logic Apps and utilize Azure Policy to restrict unauthorized configuration changes.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this issue demands immediate administrative attention. Ensure that all Logic Apps environments are patched as soon as updates are released by Microsoft and continue to monitor for any signs of unauthorized access or abnormal activity within your workflows.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
- Analyst report updated
Sources
- Azure Logic Apps Elevation of Privilege Vulnerability Vendor advisory