Executive brief
Azure Logic Apps, a cloud service for automating business workflows, contains a path traversal vulnerability that allows an attacker to access restricted files and escalate their privileges over the network. An attacker exploiting this flaw could gain unauthorized administrative access to Logic Apps instances and the data they process, potentially compromising sensitive business automation and data workflows.
Technical details
A path traversal vulnerability in Azure Logic Apps enables privilege escalation through improper pathname validation, allowing attackers to access files and directories outside intended restrictions. The vulnerability is remotely exploitable without authentication or user interaction, granting attackers full system compromise capabilities including data exfiltration and service disruption.
Affected products
- Microsoft Azure Logic Apps
Timeline
- 2026-09-17: disclosed