Improper Access Control Vulnerability in Azure Logic Apps by Microsoft
CVE-2026-83944

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
17 September 2026

What is CVE-2026-83944?

The vulnerability in Azure Logic Apps stems from inadequate access control measures, which can be exploited by unauthorized attackers to gain elevated privileges over the network. This security flaw potentially enables malicious entities to manipulate administrative functions and compromise sensitive data, highlighting the critical need for adequate security measures and timely patching to protect against unauthorized access.

Affected Version(s)

Azure Logic Apps -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.