Description
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Published: 2026-07-24
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw that allows an authorized attacker to execute arbitrary code over the Azure API Management network interface. This grants full remote code execution capabilities, enabling the attacker to compromise the service and potentially any downstream systems.

Affected Systems

Microsoft Azure API Management (APIM) is the affected product. No specific version ranges are provided in the advisory, so all published APIM instances are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 8 indicates high severity. However, the EPSS score is below 1%, suggesting exploitation attempts are currently rare. The vulnerability is not listed in CISA KEV, implying no known public exploitation. Attackers need an authorized role within APIM; therefore, internal security controls and role management are critical in limiting the attack surface.

Generated by OpenCVE AI on August 3, 2026 at 20:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure API Management patch that addresses the improper access control flaw.
  • Restrict and review role assignments to minimize privileged access, keeping it only for necessary users.
  • Enable comprehensive audit logging and actively monitor for anomalous code execution or unauthorized configuration changes.

Generated by OpenCVE AI on August 3, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Title Azure API Management (APIM) Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft azure Api Management
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:azure_api_management:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Api Management
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Api Management
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:30.242Z

Reserved: 2026-04-02T19:21:11.804Z

Link: CVE-2026-35425

cve-icon Vulnrichment

Updated: 2026-07-29T18:21:08.643Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-24T01:16:36.970

Modified: 2026-07-29T19:16:45.720

Link: CVE-2026-35425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses