rootpwn

critical · CVSS v3 10

CVE-2026-70200

CVE-2026-70200 is a critical path traversal vulnerability in Azure Logic Apps. It can allow an unauthorized network-based attacker to gain e

Overview

CVE-2026-70200 is a critical path traversal vulnerability in Azure Logic Apps. It can allow an unauthorized network-based attacker to gain elevated privileges. It matters because Logic Apps often connect to data, APIs, and identity resources, so compromise could expand access.

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Impact

Confidentiality, integrity, and availability can be affected if an attacker reaches the vulnerable component and escalates privileges. Organizations using Azure Logic Apps with broad permissions, sensitive connectors, or network exposure are most at risk. Privilege escalation may enable access to connected services, data, or management functions. The impact is defensive: focus on limiting blast radius and detecting anomalous privilege changes.

Remediation

Apply Microsoft security updates for Azure Logic Apps as soon as they are available. Review and restrict Logic Apps network exposure, disable unnecessary public endpoints, and use private endpoints or VNet integration where supported. Enforce least-privilege RBAC, managed identities, and conditional access policies. Monitor Azure Activity and Logic Apps audit logs for anomalous privilege changes, connector usage, or unexpected data access.

Affected products

  • Microsoft Azure Logic Apps

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
10
CVSS v4
EPSS

← All CVEs