Junglewise Threat Intelligence

CVE-2026-41105: Microsoft Azure Notification Service SSRF privilege escalation

CVE-2026-41105 · Severity: high · CVSS 8.1 · Published 2026-05-07

Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Microsoft Azure Notification Service, which is used to send alerts and notifications to administrators. An attacker with basic user permissions could exploit this flaw to trick the service into making unauthorized requests to internal systems. This could allow the attacker to gain higher-level administrative privileges or access sensitive data within the cloud environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Azure Monitor Action Group Notification System (CWE-918). The flaw allows an authenticated attacker with low-level privileges to submit a crafted request that the service then executes, potentially targeting internal metadata services or other private network resources. By exploiting this behavior, the attacker can achieve privilege escalation and gain unauthorized access to sensitive information. The attack is conducted over the network without requiring user interaction. Microsoft has addressed this issue in their cloud environment.

Affected products

  • Microsoft Azure Monitor Action Group Notification System

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: advisory

References