Description
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authentication flaw that enables a user who has already authorized access to gain higher privileges within Azure Spring Apps. The weakness corresponds to CWE-287, which focuses on authentication failures. Resulting in unauthorized users potentially performing actions reserved for privileged accounts, thereby compromising system confidentiality, integrity, or availability. This has been scored a high severity of 8.2 on the CVSS system.

Affected Systems

Microsoft Azure Spring Apps is the only vendor/product identified as impacted. The description does not specify version details, so all deployments of Azure Spring Apps are potentially susceptible until an official fix is provided.

Risk and Exploitability

The CVSS score of 8.2 indicates substantial risk, yet the EPSS score is below 1%, suggesting that, as of now, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. An attacker is inferred to use the network as the attack vector, abusing legitimate access to elevate privileges. Exploitation would require the ability to authenticate to the service, after which privilege levels can be increased without further authentication.

Generated by OpenCVE AI on July 31, 2026 at 09:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Microsoft patch or update for Azure Spring Apps that addresses the authentication control when it becomes available.
  • Restrict network access to Azure Spring Apps by configuring virtual network and firewall rules to limit connections to authorized IP ranges and applying least privilege to network endpoints.
  • Enforce strict user permissions and require multi‑factor authentication for privileged accounts, regularly auditing role assignments for over‑provisioned privileges.

Generated by OpenCVE AI on July 31, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
Title Azure Spring Apps Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Spring Apps
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:azure_spring_apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Spring Apps
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Azure Spring Apps
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:39.619Z

Reserved: 2026-06-04T18:15:10.952Z

Link: CVE-2026-50338

cve-icon Vulnrichment

Updated: 2026-07-14T17:44:57.683Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses