• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-50338: authenticated privilege escalation in Microsoft Azure Spring Apps

An authenticated low-privilege user can elevate privileges in Microsoft Azure Spring Apps, potentially gaining administrative control. CVE-2026-50338 affects the 7.x branch: versions 1.0.0 through before 7.3.0 are vulnerable; the issue requires network access and a low-privileged account (no user interaction). The flaw is an improper authentication weakness (CWE-287) that can allow confidentiality and integrity impact across affected deployments.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.2HIGH
EPSS
0.00517
CWE
CWE-287
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this vulnerability, so prioritize remediation; upgrade to the fixed release or immediately limit network exposure and monitor for suspicious activity.

What is CVE-2026-50338?

An authenticated low-privilege user can elevate privileges in Microsoft Azure Spring Apps, potentially gaining administrative control. CVE-2026-50338 affects the 7.x branch: versions 1.0.0 through before 7.3.0 are vulnerable; the issue requires network access and a low-privileged account (no user interaction). The flaw is an improper authentication weakness (CWE-287) that can allow confidentiality and integrity impact across affected deployments. The weakness is classified as CWE-287 (Improper Authentication).

Vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Azure Spring Apps are affected?

BRANCHAFFECTEDFIXED
7.x1.0.0 – before 7.3.07.3.0

Is CVE-2026-50338 being exploited?

Public exploit code is available.

How to fix CVE-2026-50338

  1. Upgrade Azure Spring Apps installations on the 7.x branch to 7.3.0.
  2. If you cannot upgrade immediately, restrict network access to the management and application endpoints and apply firewall rules.
  3. Rotate credentials and review audit logs for signs of privilege escalation or unauthorized access.
  4. Follow Microsoft’s guidance and monitor vendor advisories for any additional mitigations.

Frequently asked questions

Is CVE-2026-50338 being actively exploited?

Public exploit code is available for CVE-2026-50338, which increases the risk of active exploitation as of 2026-09-29.

Which Azure Spring Apps versions are affected by CVE-2026-50338?

Azure Spring Apps on the 7.x branch are affected: versions 1.0.0 through before 7.3.0 are vulnerable; 7.3.0 contains the fix.

Is there a patch for CVE-2026-50338?

Yes. Microsoft fixed the issue in Azure Spring Apps version 7.3.0; apply that update to remediate the vulnerability.

Does CVE-2026-50338 require authentication?

Yes. Exploitation requires a network connection and a low-privileged authenticated account against Azure Spring Apps; no user interaction is required.

References