Impact
A path traversal flaw in Azure Logic Apps allows an attacker to access directories outside the intended sandbox, granting them higher privileges over the network. The vulnerability is rooted in insufficient path validation (CWE‑22) and weak permission enforcement (CWE‑285). If exploited, an attacker could move from a restricted Logic App context to other protected resources, potentially modifying configurations, reading sensitive data, or disrupting services. The CVSS score of 10.0 signifies a critical severity and indicates complete system compromise if unrestricted access is achieved.
Affected Systems
Microsoft Azure Logic Apps is the affected platform. Affected versions are not specified in the advisory; any deployment of Azure Logic Apps that has not applied the vendor’s update may be vulnerable.
Risk and Exploitability
The CVSS rating of 10.0 places this vulnerability in the highest risk category, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. Based on the description, the likely attack vector is through a publicly reachable API endpoint that accepts a path parameter. If an attacker can supply a crafted path, they can traverse to privileged directories and elevate their access. Organizations should treat this as a high risk even with low current exploitation probability because a single successful exploit would grant significant control.
OpenCVE Enrichment