Executive brief
Azure Logic Apps, Microsoft's workflow automation service used by enterprises to integrate applications and services, is vulnerable to privilege escalation over the network. An unauthenticated attacker can exploit improper access controls to gain elevated permissions, potentially compromising automated business processes and sensitive data flows managed through the platform.
Technical details
The vulnerability exists in Azure Logic Apps due to improper access control mechanisms, allowing an unauthorized attacker to escalate privileges via network-based attack. The flaw permits an unauthenticated adversary to gain elevated permissions without requiring prior authentication or user interaction, leading to unauthorized control over Logic App workflows and connected resources.
Affected products
- Microsoft Azure Logic Apps
Timeline
- 2026-09-17: disclosed