Executive brief
A security flaw in the Microsoft Azure MCP Server, a component used within Azure Web Apps, allows unauthorized individuals to access sensitive information. Because a critical function lacks proper identity verification, an attacker can connect over the internet and retrieve data without needing a password or account. This could lead to the exposure of private customer information or internal system details.
Technical details
A vulnerability classified as Missing Authentication for Critical Function (CWE-306) exists in the Azure MCP Server component of Azure Web Apps. The flaw allows an unauthenticated remote attacker to invoke sensitive functions over the network without providing credentials. Successful exploitation enables the attacker to disclose sensitive information and potentially impact data integrity. Microsoft has assigned a CVSS score of 9.1, reflecting the high impact on confidentiality and integrity and the lack of required privileges or user interaction. As this is an exclusively hosted service, Microsoft typically manages the remediation on the backend.
Affected products
- Microsoft Azure Web Apps (Azure MCP Server) All versions
Timeline
- 2026-04-02: disclosed: Initial CVE receipt from Microsoft Corporation
- 2026-04-03: advisory: NVD publication date