• PATCH AVAILABLE

CVE-2026-70200: pre-auth path traversal in Microsoft Azure Logic Apps

An unauthenticated attacker can use a path traversal flaw to elevate privileges on Microsoft Azure Logic Apps (CVE-2026-70200). The weakness is CWE-22 path traversal and can be exploited remotely without user interaction or valid credentials. Microsoft lists the Azure Logic Apps branch as affected; no fixed versions are specified in the provided facts. Exploitation may enable wide impact to confidentiality, integrity, and availability over the network.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.006
CWE
CWE-22
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is remotely exploitable without authentication, so prioritize mitigations that remove internet exposure and apply Microsoft’s fixes or guidance immediately.

What is CVE-2026-70200?

An unauthenticated attacker can use a path traversal flaw to elevate privileges on Microsoft Azure Logic Apps (CVE-2026-70200). The weakness is CWE-22 path traversal and can be exploited remotely without user interaction or valid credentials. Microsoft lists the Azure Logic Apps branch as affected; no fixed versions are specified in the provided facts. Exploitation may enable wide impact to confidentiality, integrity, and availability over the network. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Azure Logic Apps are affected?

BRANCHAFFECTEDFIXED
Azure Logic Apps-

Is CVE-2026-70200 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-70200

  1. Apply Microsoft’s vendor updates or guidance for Azure Logic Apps as provided in the vendor advisory.
  2. Restrict network access to Azure Logic Apps endpoints—limit public exposure and use network controls or IP allowlists.
  3. Monitor Logic Apps logs and alerting for unusual file-path access patterns or unexpected privilege changes.
  4. Implement additional compensating controls (least privilege, runtime protections) until vendor fixes are confirmed applied.

Frequently asked questions

Is CVE-2026-70200 being actively exploited?

No public reports of exploitation exist as of 2026-09-29.

Which Azure Logic Apps versions are affected by CVE-2026-70200?

The Azure Logic Apps branch is listed as affected; the provided facts do not specify particular version numbers or fixed releases.

Is there a patch for CVE-2026-70200?

A patch is reported available according to the facts; check Microsoft’s advisory for the exact update and installation instructions.

Does CVE-2026-70200 require authentication?

No — the vulnerability can be exploited without authentication or user interaction against Azure Logic Apps.

References