CVE-2026-42823: Azure Logic Apps Elevation of Privilege Vulnerability
Published May 12, 2026
·Updated
Azure Logic Apps Elevation of Privilege Vulnerability
Other sources
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
3 affected components
Microsoft Azure Logic Apps
Microsoft Azure Logic Apps
Microsoft Azure Logic Apps
Event History
May 12, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverity
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
News Published
via Dark Reading·09:03 PM
May 13, 2026
News Published
via Dark Reading·12:06 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-42823?
CVE-2026-42823 is considered a high-severity vulnerability due to the risk of privilege escalation.
2
How do I fix CVE-2026-42823?
To fix CVE-2026-42823, apply the latest security updates provided by Microsoft for Azure Logic Apps.
3
What types of attacks can CVE-2026-42823 facilitate?
CVE-2026-42823 can facilitate unauthorized privilege escalation attacks within Azure Logic Apps.
4
Who is affected by CVE-2026-42823?
Users of Microsoft Azure Logic Apps are affected by CVE-2026-42823 due to improper access control.
5
What are the potential consequences of CVE-2026-42823?
The potential consequences of CVE-2026-42823 include unauthorized access to sensitive data and systems.