Description
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control in Azure App Service for Linux permits an unauthorized attacker to elevate privileges over the network. This weakness allows a non‑privileged entity to gain higher level permissions than intended, potentially resulting in unauthorized configuration changes, data exposure, or further compromise. The vulnerability falls under the Access Control Weakness category (CWE-284).

Affected Systems

Microsoft Azure App Service for Linux is affected. No specific patched or unpatched version information is provided in the CNA data, so all instances of this product that are currently deployed may be at risk until an update is applied.

Risk and Exploitability

The CVSS score of 10 indicates maximum severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves a network connection to the App Service endpoint, where no prior authentication is required to gain elevated privileges. Although exploitation conditions are simple, the potential impact remains significant.

Generated by OpenCVE AI on August 3, 2026 at 20:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and deploy the latest security update for Azure App Service for Linux from the Microsoft Security Update Guide
  • Restrict network and service endpoints to trusted IP ranges only to limit unauthorized access to privileged APIs
  • Apply the principle of least privilege by assigning only the minimum required RBAC roles to users and services interacting with Azure App Service

Generated by OpenCVE AI on August 3, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Title Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure App Service
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:azure_app_service:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure App Service
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure App Service Azure App Service For Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:33.455Z

Reserved: 2026-07-01T21:14:44.616Z

Link: CVE-2026-58630

cve-icon Vulnrichment

Updated: 2026-07-24T19:54:07.273Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T15:18:47.847

Modified: 2026-08-06T00:44:46.057

Link: CVE-2026-58630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:15:04Z

Weaknesses