Impact
Improper access control in Azure App Service for Linux permits an unauthorized attacker to elevate privileges over the network. This weakness allows a non‑privileged entity to gain higher level permissions than intended, potentially resulting in unauthorized configuration changes, data exposure, or further compromise. The vulnerability falls under the Access Control Weakness category (CWE-284).
Affected Systems
Microsoft Azure App Service for Linux is affected. No specific patched or unpatched version information is provided in the CNA data, so all instances of this product that are currently deployed may be at risk until an update is applied.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector involves a network connection to the App Service endpoint, where no prior authentication is required to gain elevated privileges. Although exploitation conditions are simple, the potential impact remains significant.
OpenCVE Enrichment