• PATCH AVAILABLE

CVE-2026-65816: pre-auth privilege escalation in Microsoft Azure Web Apps

An unauthenticated attacker can elevate privileges against Azure Web Apps by exploiting incorrect name or reference resolution, allowing remote compromise of confidentiality, integrity, and availability. CVE-2026-65816 is tracked as a CWE-706 issue. Microsoft identifies the flaw in Azure Web Apps but does not list specific fixed releases in the provided facts; an attacker only needs network access to reach the vulnerable service and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00974
CWE
CWE-706
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, unauthenticated elevation-of-privilege flaw with maximum severity and no user interaction required, so prioritize mitigation for internet-facing Azure Web Apps immediately.

What is CVE-2026-65816?

An unauthenticated attacker can elevate privileges against Azure Web Apps by exploiting incorrect name or reference resolution, allowing remote compromise of confidentiality, integrity, and availability. CVE-2026-65816 is tracked as a CWE-706 issue. Microsoft identifies the flaw in Azure Web Apps but does not list specific fixed releases in the provided facts; an attacker only needs network access to reach the vulnerable service and does not require valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Microsoft Azure Web Apps are affected?

BRANCHAFFECTEDFIXED
Azure Web Apps-

Is CVE-2026-65816 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-65816

  1. Apply the vendor patch or updates for Azure Web Apps as directed by Microsoft.
  2. Restrict network exposure of Azure Web Apps endpoints to trusted networks and use network ACLs or private endpoints.
  3. Monitor application and access logs for unusual privilege changes or anomalous activity.
  4. Follow Microsoft's guidance for any additional configuration changes or mitigations they publish.

Frequently asked questions

Is CVE-2026-65816 being actively exploited?

There are no public reports of exploitation of CVE-2026-65816 as of 2026-09-29.

Which Azure Web Apps versions are affected by CVE-2026-65816?

The facts indicate Azure Web Apps is affected but do not specify particular version numbers or builds as fixed in the provided data.

Is there a patch for CVE-2026-65816?

Yes; the facts state a patch is available from Microsoft for Azure Web Apps—apply the vendor update and follow their guidance.

Does CVE-2026-65816 require authentication?

No; CVE-2026-65816 can be exploited without credentials and does not require user interaction, only network access to the service.

References