Executive brief
Microsoft Azure Logic Apps, a cloud service used to automate workflows and integrate apps and data, contains a security flaw that allows for unauthorized privilege escalation. An attacker with basic access to the network can exploit this weakness to gain higher-level administrative permissions. This could lead to full control over automated business processes, unauthorized access to sensitive integrated data, and significant disruption of corporate operations.
Technical details
A privilege escalation vulnerability exists in Microsoft Azure Logic Apps due to improper access control (CWE-284). The flaw allows an authenticated attacker with low-privileged access to exploit the service over a network without any user interaction. Because the vulnerability has a 'Changed' scope in the CVSS metric, an attacker can potentially impact components beyond the Logic Apps environment itself, leading to a full compromise of confidentiality, integrity, and availability. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.
Affected products
- Microsoft Logic Apps
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft published the security advisory.