CVE-2026-69400: Azure Logic Apps Elevation of Privilege Vulnerability
Azure Logic Apps Elevation of Privilege Vulnerability
Other sources
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
The vulnerability is described as exploitable by an unauthorized attacker over a network, and the vector indicates no privileges are required. User interaction is required.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow elevation of privilege. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability, with scope changed.
What weakness is involved?
The issue is classified as path traversal: improper limitation of a pathname to a restricted directory. This can enable access beyond intended directory boundaries.