Junglewise Threat Intelligence

CVE-2026-70200: Azure Logic Apps path traversal privilege elevation

CVE-2026-70200 · Severity: critical · CVSS 10 · Published 2026-09-17

Technologies: Microsoft Azure Logic Apps. Vendors: Microsoft.

Executive brief

Azure Logic Apps, a cloud service for automating business workflows, contains a path traversal vulnerability that allows an attacker to access restricted files and escalate their privileges over the network. An attacker exploiting this flaw could gain unauthorized administrative access to Logic Apps instances and the data they process, potentially compromising sensitive business automation and data workflows.

Technical details

A path traversal vulnerability in Azure Logic Apps enables privilege escalation through improper pathname validation, allowing attackers to access files and directories outside intended restrictions. The vulnerability is remotely exploitable without authentication or user interaction, granting attackers full system compromise capabilities including data exfiltration and service disruption.

Affected products

  • Microsoft Azure Logic Apps

Timeline

  • 2026-09-17: disclosed

References

Related threats