• PATCH AVAILABLE

CVE-2026-83944: pre-auth privilege escalation in Microsoft Azure Logic Apps

An unauthenticated attacker can elevate privileges on Azure Logic Apps, potentially gaining higher-level access to workflows and resources; this is tracked as CVE-2026-83944. Microsoft lists the issue as affecting the Azure Logic Apps branch but does not name specific versions; the flaw requires network access and does not require valid credentials or user interaction. A patch is available from the vendor.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.1CRITICAL
EPSS
0.00442
CWE
CWE-284
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this bypass requires no authentication, so exposed Logic Apps endpoints should be treated as high risk — apply Microsoft’s update or follow vendor mitigation guidance immediately.

What is CVE-2026-83944?

An unauthenticated attacker can elevate privileges on Azure Logic Apps, potentially gaining higher-level access to workflows and resources; this is tracked as CVE-2026-83944. Microsoft lists the issue as affecting the Azure Logic Apps branch but does not name specific versions; the flaw requires network access and does not require valid credentials or user interaction. A patch is available from the vendor.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Microsoft Azure Logic Apps are affected?

BRANCHAFFECTEDFIXED
Azure Logic Apps-

Is CVE-2026-83944 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-83944

  1. Apply Microsoft’s update or vendor guidance for Azure Logic Apps as soon as possible.
  2. If you cannot patch immediately, restrict network exposure of Logic Apps endpoints to trusted IP ranges.
  3. Monitor Azure activity logs and alerts for unusual privilege changes and workflow modifications.
  4. Implement least-privilege access controls and review connector and managed identity permissions.

Frequently asked questions

Is CVE-2026-83944 being actively exploited?

There are no public reports of active exploitation of CVE-2026-83944 as of 2026-09-30; it is not listed in CISA’s KEV catalog and no public exploit code is known.

Which Azure Logic Apps versions are affected by CVE-2026-83944?

Microsoft describes the issue as affecting the Azure Logic Apps branch; the advisory does not list specific version numbers.

Is there a patch for CVE-2026-83944?

Yes. Microsoft has indicated a patch is available for Azure Logic Apps; follow the vendor update instructions to remediate.

Does CVE-2026-83944 require authentication?

No. The vulnerability allows privilege elevation without valid credentials, so it can be reached by an unauthenticated network actor.

References