CVE-2026-32171 Details
Description
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
A vulnerability allowing elevation of privilege has been identified in Azure Logic Apps. This issue arises from insufficiently protected credentials, which could enable an authorized attacker to gain administrative privileges over a network. Exploitation could involve creating a forged authentication token to access administrative function APIs, potentially allowing the retrieval of keys, access to the file system, and deployment of unauthorized code within the Logic Apps environment.
Customers are protected through automatic service-side updates. However, for existing Logic Apps created with WEBSITE_AUTH_ENCRYPTION_KEY as an environment variable, a small update is required to fully mitigate the issue. New or updated Logic Apps are automatically mitigated without any customer action.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32171 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft azure logic apps | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |