DIRAS TAKE
Urgent: this is remotely exploitable without authentication, so prioritize mitigations that remove internet exposure and apply Microsoft’s fixes or guidance immediately.
What is CVE-2026-70200?
An unauthenticated attacker can use a path traversal flaw to elevate privileges on Microsoft Azure Logic Apps (CVE-2026-70200). The weakness is CWE-22 path traversal and can be exploited remotely without user interaction or valid credentials. Microsoft lists the Azure Logic Apps branch as affected; no fixed versions are specified in the provided facts. Exploitation may enable wide impact to confidentiality, integrity, and availability over the network. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Azure Logic Apps are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Azure Logic Apps | - |
Is CVE-2026-70200 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-70200
- Apply Microsoft’s vendor updates or guidance for Azure Logic Apps as provided in the vendor advisory.
- Restrict network access to Azure Logic Apps endpoints—limit public exposure and use network controls or IP allowlists.
- Monitor Logic Apps logs and alerting for unusual file-path access patterns or unexpected privilege changes.
- Implement additional compensating controls (least privilege, runtime protections) until vendor fixes are confirmed applied.
Frequently asked questions
Is CVE-2026-70200 being actively exploited?
No public reports of exploitation exist as of 2026-09-29.
Which Azure Logic Apps versions are affected by CVE-2026-70200?
The Azure Logic Apps branch is listed as affected; the provided facts do not specify particular version numbers or fixed releases.
Is there a patch for CVE-2026-70200?
A patch is reported available according to the facts; check Microsoft’s advisory for the exact update and installation instructions.
Does CVE-2026-70200 require authentication?
No — the vulnerability can be exploited without authentication or user interaction against Azure Logic Apps.
References
- nvd.nist.gov/vuln/detail/CVE-2026-70200
- cve.org/CVERecord?id=CVE-2026-70200
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70200
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026