CVE-2026-70200
largeUnauthenticated path traversal privilege escalation in Azure Logic Apps
CVE-2026-70200 is a path traversal flaw (CWE-22, improper limitation of a pathname to a restricted directory) in Microsoft's Azure Logic Apps cloud integration service, compounded by an improper authorization weakness (CWE-285). According to Microsoft's CVSS scoring, a remote, unauthenticated attacker can trigger it over the network with low attack complexity and no user interaction or privileges required. Successful exploitation changes the security scope and yields high confidentiality and integrity impact — effectively elevated privileges and access to resources outside the intended restriction boundary, with no availability impact. Any organization running workflows on Azure Logic Apps is potentially affected, since the flaw resides in the first-party Microsoft-managed service rather than customer-patched software. Exploitation status is currently calm: no public proof of concept is known, no in-the-wild abuse has been reported, and the flaw is not yet in CISA's KEV catalog.
What to do: Because this is a Microsoft-managed PaaS, remediation is deployed server-side by Microsoft rather than via customer patching — monitor the Microsoft advisory for affected service components and confirm your region/workflows are covered by the fix. In the meantime, restrict Logic Apps inbound access (request triggers limited to specific IP ranges, service tags, or inbound traffic policies) and audit workflow run history, file-system and connector activity, and stored credentials for signs of unauthorized access or privilege changes.
| Microsoft Azure Logic Apps (first-party cloud service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
- Weakness
- CWE-22, CWE-285
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.