CVE-2026-26135Disclosure(microsoft / azure_custom_locations_resource_provider)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_custom_locations_resource_provider systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_custom_locations_resource_provider

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-03); latest day: 2
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
azure_custom_locations_resource_provider

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-04-03: 5Mentions · 2026-04-07: 2Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-03: 4Technical Details · 2026-04-07: 204-0304-07
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-035
Disclosure3General2
2026-04-072
Disclosure1Patch1
Full discourse7 posts
  • Firmis Labs@FirmisLabs
    Disclosure

    CVE-2026-26135 · NIST 9.6/10 https://nvd.nist.gov/vuln/detail/CVE-2026-26135

    Post summary

    A new vulnerability, CVE-2026-26135, has been disclosed with a high severity rating of 9.6/10 on NIST. The provided link directs to the NVD entry for further details.

    1000026
    1 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Microsoft released Security Update to address an Elevation of Privilege Vulnerability in Microsoft Azure Custom Locations Resource Provider. #CVE-2026-26135 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26135

    Post summary

    Microsoft has issued a security update for CVE‑2026‑26135, addressing an elevation‑of‑privilege flaw in the Azure Custom Locations Resource Provider.

    00000188
    8.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26135 Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26135

    Post summary

    A new SSRF vulnerability (CVE-2026-26135) in Azure Custom Locations Resource Provider could enable an authorized attacker to elevate privileges across the network.

    00000100
    56.9K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-26135 📊 Severity: 9.6 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-26135 #CVE-2026-26135 #CVE #Critical #CyberSecurity #InfoSec https://t.co/bcOJmaTLlG

    Post summary

    The tweet announces CVE-2026-26135 with a severity rating of 9.6 but provides no technical details, PoC, or mitigation information.

    0000039
    123 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26135 - Critical Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26135/ https://t.co/zXIxWu7PPm

    Post summary

    A newly disclosed Azure SSRF vulnerability (CVE-2026-26135) that enables privilege escalation, presented with basic technical details but lacking exploit code or mitigation advice.

    0000052
    160 followersView on X
  • dbugs@ptdbugs
    General

    Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability CVE: CVE-2026-26135 PT ID: PT-2026-29902 Vendor: Microsoft Product: Azure Custom Locations Resource Provider CVSS: 9.6 Credits: n/a Description: Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-26135 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26135 #dbugs_vuln

    Post summary

    An Azure Custom Locations Resource Provider vulnerability (CVE-2026-26135) with SSRF-based privilege escalation is documented, but no PoC, exploit, or patch details are provided.

    0000066
    768 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26135: CRITICAL] Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.#cve,CVE-2026-26135,#cybersecurity https://cvefind.com/CVE-2026-26135

    Post summary

    A critical server‑side request forgery vulnerability in Azure Custom Locations Resource Provider that allows authorized attackers to elevate privileges over a network has been disclosed.

    0000041
    610 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_custom_locations_resource_provider---

Explore more