Description
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Elevation of Privilege
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in Azure Logic Apps allows an attacker to access directories outside the intended sandbox, granting them higher privileges over the network. The vulnerability is rooted in insufficient path validation (CWE‑22) and weak permission enforcement (CWE‑285). If exploited, an attacker could move from a restricted Logic App context to other protected resources, potentially modifying configurations, reading sensitive data, or disrupting services. The CVSS score of 10.0 signifies a critical severity and indicates complete system compromise if unrestricted access is achieved.

Affected Systems

Microsoft Azure Logic Apps is the affected platform. Affected versions are not specified in the advisory; any deployment of Azure Logic Apps that has not applied the vendor’s update may be vulnerable.

Risk and Exploitability

The CVSS rating of 10.0 places this vulnerability in the highest risk category, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. Based on the description, the likely attack vector is through a publicly reachable API endpoint that accepts a path parameter. If an attacker can supply a crafted path, they can traverse to privileged directories and elevate their access. Organizations should treat this as a high risk even with low current exploitation probability because a single successful exploit would grant significant control.

Generated by OpenCVE AI on September 18, 2026 at 23:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Microsoft’s latest patch for Azure Logic Apps as soon as possible
  • Configure Azure Firewall or NSG rules to restrict external access to Logic App endpoints, limiting exposure to only trusted networks
  • Enable Azure Private Link for Logic Apps to expose services only over a private subnet and monitor audit logs for any path traversal or unauthorized access attempts

Generated by OpenCVE AI on September 18, 2026 at 23:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_logic_apps:-:*:*:*:*:*:*:*

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Title Azure Logic Apps Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Logic Apps
Weaknesses CWE-22
CWE-285
CPEs cpe:2.3:a:microsoft:azure_logic_apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Logic Apps
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Logic Apps
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:12:11.911Z

Reserved: 2026-08-03T23:51:35.008Z

Link: CVE-2026-70200

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:34.754Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T23:18:36.113

Modified: 2026-09-25T20:08:36.207

Link: CVE-2026-70200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-285

    Improper Authorization