Microsoft Azure Logic Apps Improper Access Control Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability has been identified in Azure Logic Apps that involves improper access control, allowing an authorized attacker to elevate privileges over a network. This issue affects several different versions of Azure Logic Apps.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain elevated rights or access within the application.

Remediation

Customers who have received an Azure Service Health notification for this issue can reference Tracking ID: 1P8-C0G in the Azure portal to review the applicable guidance and required remediation steps. Additionally, customers subscribed to the Security Update Guide will be notified when this CVE is revised to reflect updated guidance or mitigation details.

Added: May 12, 2026, 7:06 PM
Updated: May 12, 2026, 7:06 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.