ZeroHour

CVE-2026-70200

large

Unauthenticated path traversal privilege escalation in Azure Logic Apps

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-70200 is a path traversal flaw (CWE-22, improper limitation of a pathname to a restricted directory) in Microsoft's Azure Logic Apps cloud integration service, compounded by an improper authorization weakness (CWE-285). According to Microsoft's CVSS scoring, a remote, unauthenticated attacker can trigger it over the network with low attack complexity and no user interaction or privileges required. Successful exploitation changes the security scope and yields high confidentiality and integrity impact — effectively elevated privileges and access to resources outside the intended restriction boundary, with no availability impact. Any organization running workflows on Azure Logic Apps is potentially affected, since the flaw resides in the first-party Microsoft-managed service rather than customer-patched software. Exploitation status is currently calm: no public proof of concept is known, no in-the-wild abuse has been reported, and the flaw is not yet in CISA's KEV catalog.

What to do: Because this is a Microsoft-managed PaaS, remediation is deployed server-side by Microsoft rather than via customer patching — monitor the Microsoft advisory for affected service components and confirm your region/workflows are covered by the fix. In the meantime, restrict Logic Apps inbound access (request triggers limited to specific IP ranges, service tags, or inbound traffic policies) and audit workflow run history, file-system and connector activity, and stored credentials for signs of unauthorized access or privilege changes.

Affected
Microsoft Azure Logic Apps (first-party cloud service)
Estimated exposure
largeplausibly on the order of 100k+ enterprise users and tens of thousands of Azure tenant workflows (estimate; no official counts published) — Azure Logic Apps is a mainstream first-party Azure enterprise integration service with broad commercial deployment, but Microsoft publishes no tenant or workflow counts, so this is an order-of-magnitude estimate rather than a scanned…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-22, CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.