Microsoft Azure Logic Apps — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Azure Logic Apps, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (8)
CVE-2026-83944 — CVSS 10.0 (critical): Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70200 — CVSS 10.0 (critical): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to…
CVE-2026-42823 — CVSS 9.9 (critical): Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-56161 — CVSS 9.6 (critical): Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-69400 — CVSS 9.6 (critical): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to…
CVE-2026-32171 — CVSS 8.8 (high): Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-21227 — CVSS 8.2 (high): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to…