Executive brief
Microsoft Azure Spring Apps, a managed service for hosting Spring Boot applications, contains a security flaw that allows an authorized user to gain higher levels of access than intended. An attacker who already has basic access to the environment could exploit this to take control of administrative functions or access sensitive data. This could lead to unauthorized changes to applications or the exposure of internal corporate information.
Technical details
An improper authentication vulnerability (CWE-287) exists in Microsoft Azure Spring Apps versions 1.0.0 through 7.3.0. The flaw allows a network-based attacker with low-privileged credentials to bypass authentication checks and elevate their privileges within the environment. While the attack requires high complexity (AC:H), successful exploitation results in a scope change (S:C), potentially impacting the confidentiality and integrity of the underlying cloud resources. Microsoft has addressed this issue in version 7.3.0.
Affected products
- Microsoft Azure Spring Apps 1.0.0 to 7.3.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory