Junglewise Threat Intelligence

CVE-2026-26135: Microsoft Azure Custom Locations Resource Provider SSRF privilege escalation

CVE-2026-26135 · Severity: critical · CVSS 9.6 · Published 2026-04-03

Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Azure service used to manage custom locations for cloud resources. An authorized user could exploit this flaw to gain higher levels of access than they should have, potentially allowing them to view or modify sensitive data across the network. This could lead to unauthorized administrative control over cloud infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Azure Custom Locations Resource Provider (RP). The flaw is categorized as CWE-918 and allows an authenticated attacker with low privileges to send crafted network requests from the server side. By exploiting this, the attacker can achieve privilege escalation and gain unauthorized access to sensitive information or perform actions with higher-level permissions. The vulnerability is rated with a CVSS 3.1 score of 9.6 due to the potential for scope change and high impact on confidentiality and integrity. As this is an exclusively hosted service, Microsoft typically manages the remediation on the backend.

Affected products

  • Microsoft Azure Custom Locations Resource Provider All versions

Timeline

  • 2026-04-03: advisory: Initial disclosure by Microsoft and NVD

References