Junglewise Threat Intelligence

CVE-2026-69400: Microsoft Azure Logic Apps path traversal privilege escalation

CVE-2026-69400 · Severity: critical · CVSS 9.6 · Published 2026-08-20

Technologies: Microsoft Azure Logic Apps. Vendors: Microsoft.

Executive brief

Azure Logic Apps is a cloud-based workflow automation service used by enterprises to integrate applications and data processing. A path traversal vulnerability allows attackers on the network to bypass access restrictions and elevate their privileges within the service, potentially gaining unauthorized access to sensitive workflows and data processed by Logic Apps instances.

Technical details

The vulnerability is a path traversal (directory traversal) flaw in Azure Logic Apps that fails to properly restrict pathname access to authorized directories. An attacker with network reachability to an affected Logic Apps instance can craft malicious requests that traverse the file system to access restricted resources and execute unauthorized actions. The vulnerability enables privilege escalation, allowing an attacker to gain elevated permissions over the network without prior authentication. No patch availability information is provided in the advisory.

Affected products

  • Microsoft Azure Logic Apps

Timeline

  • 2026-08-20: disclosed

References

Related threats