Impact
The vulnerability is a path traversal flaw (CWE‑22) that allows an unauthenticated attacker to reference files outside of a designated directory in Azure Logic Apps. By tricking the service into accessing an unauthorized location, the attacker can gain elevated privileges over the network, potentially compromising other connected resources or services.
Affected Systems
Microsoft Azure Logic Apps is affected. No specific product version information is available in the current advisory.
Risk and Exploitability
The CVSS base score is 9.6, placing it in the Critical severity range. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is inferred to be a remote network attack that can be performed from any client with connectivity to the Logic App. Because the flaw permits privilege escalation, the impact on confidentiality, integrity, and availability is significant if an attacker can fully control the Logic App environment.
OpenCVE Enrichment