Microsoft disclosed and patched two Azure Logic Apps Elevation of Privilege vulnerabilities, tracked as CVE-2026-42823 and CVE-2026-32171, through its Security Update Guide. Both advisories identify privilege-escalation issues affecting the Azure Logic Apps service, expanding the list of cloud platform flaws that could allow an attacker to gain higher permissions within impacted environments.
The vulnerabilities were published in separate Microsoft advisories, with CVE-2026-32171 appearing first and CVE-2026-42823 added later. Microsoft provided the notices via MSRC update entries rather than detailed public write-ups, indicating customers should review the Security Update Guide and apply the relevant Azure-side remediations or service updates associated with their Logic Apps deployments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2026-42823, another Azure Logic Apps Elevation of Privilege vulnerability, to its Security Update Guide. The reference indicates the advisory was published on 2026-05-12.
Microsoft added CVE-2026-32171, an Azure Logic Apps Elevation of Privilege vulnerability, to its Security Update Guide. The reference indicates the advisory was published on 2026-04-14.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.