Path Traversal Vulnerability in Azure Logic Apps by Microsoft
CVE-2026-69400

9.6CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
20 August 2026

What is CVE-2026-69400?

A path traversal vulnerability in Azure Logic Apps enables unauthorized attackers to bypass security restrictions, potentially elevating privileges within network environments. By exploiting improper limitations on a pathname to a restricted directory, attackers can gain unauthorized access to sensitive operations, posing risks to data integrity and confidentiality. It is crucial for users to apply the latest security patches to mitigate this risk.

Affected Version(s)

Azure Logic Apps -

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.