Executive brief
Azure MCP Server is a cloud integration service used to connect external applications with Microsoft Azure. An authorized user can exploit a server-side request forgery flaw to elevate their privileges by forcing the server to make unauthorized requests on their behalf to sensitive Azure resources, potentially gaining access to data or functionality they should not have.
Technical details
Server-Side Request Forgery (SSRF, CWE-918) in Azure MCP Server allows an authenticated attacker to bypass input validation and redirect the server to make arbitrary HTTP requests to internal or external URLs. The vulnerability exists in the ResourceHealth and Kusto tools due to insufficient URL validation before the server fetches remote resources. An attacker with valid credentials can craft a malicious URL to access restricted Azure resources or internal services. The fix adds resource ID validation (Azure.Core.ResourceIdentifier.Parse) and cluster URI validation with domain suffix and hostname allowlisting. Patches are available in Azure.Mcp 1.0.2 and later, plus 2.0.0-beta.17 and later across NuGet, npm, and PyPI distributions.
Affected products
- Microsoft Azure.Mcp 1.0.0–1.0.1; 2.0.0-beta.1–2.0.0-beta.16
- Microsoft msmcp-azure 2.0.0b14–2.0.0b16
Timeline
- 2026-03-10: disclosed: Public disclosure via OSV database
- 2026-02-03: patched: Fix committed with URL validation improvements
- 2026-03-10: patched: Patches released: Azure.Mcp 1.0.2, 2.0.0-beta.17, and npm/PyPI equivalents