CVE-2026-42823
Microsoft · Published May 12, 2026
9.9
CVSS v3.1
CRITICALPatch availableGet patch
Description
Azure Logic Apps Elevation of Privilege Vulnerability. Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Affected Products
- Azure Logic Apps
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C