CVE-2026-42823Disclosure(microsoft / azure_logic_apps)

LOWCVSS 9.9 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_logic_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_logic_apps

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-12); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
azure_logic_apps

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-12: 3Mentions · 2026-05-13: 2Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 205-1205-13
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-123
Disclosure2Patch1
2026-05-132
General1Patch1
Full discourse5 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The post lists numerous critical CVEs across Microsoft, Ivanti, Fortinet, SAP, and Adobe, detailing RCE, SQL injection, and privilege escalation flaws while emphasizing the urgent need for vendor patches and mitigations.

    000211.4K
    11.7K followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-41096 9.8 Microsoft Windows DNS ・CVE-2026-42823 9.9 Azure Logic Apps ・CVE-2026-42826 10  Azure DevOps ・CVE-2026-42898 9.9 Microsoft Dynamics 365 (オンプレミス)

    Post summary

    The tweet lists several high-scoring CVEs affecting Microsoft products but does not provide PoC, exploit, or patch details, making it a general mention.

    10000172
    85 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-42823 — CVSS 9.9/10 ██████████ Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/JiP7zSheXm

    Post summary

    The tweet announces CVE-2026-42823, a critical privilege‑escalation flaw in Azure Logic Apps, and informs that a patch is available immediately.

    1000065
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42823 Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-42823 ----- Traducción: CVE-2026-42823 Control de acceso inapropiado en Azure Logic Apps permite a … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑42823, highlighting improper access control in Azure Logic Apps that could let an authorized user elevate privileges across a network.

    0000037
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42823 Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-42823

    Post summary

    The post announces CVE‑2026‑42823, noting that improper access control in Azure Logic Apps permits privilege escalation over a network, but provides no PoC, exploit, patch, or active attack details.

    00000286
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_logic_apps---

Explore more