critical · CVSS v3 10
CVE-2026-83944
CVE‑2026‑83944 exposes an improper access control flaw in Microsoft Azure Logic Apps, enabling an attacker to elevate privileges across a ne
Overview
CVE‑2026‑83944 exposes an improper access control flaw in Microsoft Azure Logic Apps, enabling an attacker to elevate privileges across a network. The vulnerability can be exploited without authentication, allowing lateral movement and potential data exfiltration. It is critical for any organization using Logic Apps for integration or automation.
Description
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Impact
Confidentiality: unauthorized access to data processed by Logic Apps. Integrity: potential modification or deletion of integration workflows. Availability: risk of service disruption through malicious workflow execution. The primary impact is on Azure customers who deploy Logic Apps for business processes, exposing them to lateral movement and data compromise.
Remediation
['Apply the latest Azure Logic Apps update or patch released by Microsoft.', 'Review and tighten RBAC assignments—ensure only necessary users/groups have contributor or owner roles.', 'Enable Azure AD Conditional Access policies to restrict Logic Apps management access to trusted networks and devices.', 'Configure network restrictions (e.g., service endpoints, private link) to limit inbound traffic to Logic Apps.', 'Enable Azure Security Center recommendations and continuous monitoring for anomalous workflow activity.', 'Audit and rotate any service principals or managed identities that have elevated permissions.']
Risk context
The CVSS v3 score of 10.0 and critical severity indicate a high‑risk vulnerability with immediate mitigation required. No EPSS data is available, but the lack of authentication bypass and potential for widespread lateral movement make this a top priority for defenders.
Affected products
- Microsoft Azure Logic Apps
- Azure Logic Apps Standard
- Azure Logic Apps Consumption
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 10
- CVSS v4
- —
- EPSS
- —