CVE-2026-50338: Azure Spring Apps Elevation of Privilege Vulnerability
Published Jul 14, 2026
·Updated
Azure Spring Apps Elevation of Privilege Vulnerability
Other sources
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft Azure Spring Apps<7.3.0
7.3.0
Microsoft Azure Spring Cloud<7.3.0
Remediation
Event History
Jul 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-50338?
The severity of CVE-2026-50338 is rated high with a score of 8.2.
2
What kind of vulnerability is CVE-2026-50338?
CVE-2026-50338 is an elevation of privilege vulnerability within Azure Spring Apps.
3
Who is affected by CVE-2026-50338?
CVE-2026-50338 affects users of Microsoft Azure Spring Apps and Microsoft Azure Spring Cloud.
4
How do I fix CVE-2026-50338?
To fix CVE-2026-50338, you need to apply the available patch provided by Microsoft.
5
What impact does CVE-2026-50338 have on security?
CVE-2026-50338 allows an authorized attacker to elevate privileges, potentially compromising sensitive data.