Improper Access Control Vulnerability in Azure Logic Apps by Microsoft
CVE-2026-42823

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

What is CVE-2026-42823?

The vulnerability in Azure Logic Apps arises from improper access control mechanisms that allow an authorized attacker to elevate privileges over a network. This can potentially enable unauthorized actions and access to sensitive data, compromising the overall integrity and security of applications using Azure Logic Apps. Proper security measures and adherence to best practices are essential for mitigating this vulnerability.

Affected Version(s)

Azure Logic Apps -

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.