Junglewise Threat Intelligence

CVE-2026-42823: Microsoft Azure Logic Apps privilege escalation

CVE-2026-42823 · Severity: critical · CVSS 9.9 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

Microsoft Azure Logic Apps, a cloud service used to automate workflows and integrate apps and data, contains a security flaw that allows for unauthorized privilege escalation. An attacker with basic access to the network can exploit this weakness to gain higher-level administrative permissions. This could lead to full control over automated business processes, unauthorized access to sensitive integrated data, and significant disruption of corporate operations.

Technical details

A privilege escalation vulnerability exists in Microsoft Azure Logic Apps due to improper access control (CWE-284). The flaw allows an authenticated attacker with low-privileged access to exploit the service over a network without any user interaction. Because the vulnerability has a 'Changed' scope in the CVSS metric, an attacker can potentially impact components beyond the Logic Apps environment itself, leading to a full compromise of confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.

Affected products

  • Microsoft Logic Apps

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Microsoft published the security advisory.

References