Security researcher Binary Security disclosed five critical cross-tenant elevation-of-privilege flaws in Azure Logic Apps API Connections that could allow an attacker to invoke a victim tenant’s configured API connection and use its credentials against the connected backend service. The reported attack paths included traversal in Azure Resource Manager (ARM) DynamicInvoke requests to target connections in other tenants, potentially exposing Azure Key Vault secrets, and undocumented dynamic endpoints such as DynamicList that reportedly enabled cross-tenant SQL operations.
A separate flaw affecting Consumption Logic Apps reportedly allowed replacement of a validated API endpoint through the host.api.RuntimeUrl property; an initial remediation was bypassed because URL validation preceded path normalization. Microsoft has fixed the reported issues and awarded the researcher a combined $200,000 bounty for the five critical vulnerabilities. No CVE identifiers or evidence of in-the-wild exploitation were provided in the disclosure.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
The researcher reported submitting five critical Azure elevation-of-privilege vulnerabilities involving API Connections. Microsoft fixed the vulnerabilities described in the report and awarded total rewards of $200,000, according to the author.
Microsoft initially required a submitted RuntimeUrl path to match the expected endpoint, but the researcher reportedly bypassed this control because validation occurred before URL-path normalization. The runtime and APIM consequently interpreted the path differently.
The researcher found that a Consumption Logic Apps workflow could supply a different host.api.RuntimeUrl after ownership validation of host.connection. A substituted azure-apihub.net URL reportedly received the required Authorization header, enabling use of another API endpoint.
Microsoft subsequently blocked the dynamic endpoints identified by the researcher, including endpoints in the DynamicInvoke and DynamicList family.
The researcher subsequently found that the undocumented DynamicList endpoint accepted traversable path parameters. A proof of concept reportedly used it to execute an arbitrary SQL INSERT against an Azure SQL database connected by a different tenant.
Microsoft initially mitigated the reported DynamicInvoke issue with path restrictions or blacklisting, rather than changing the underlying credential-routing design, according to the researcher.
A researcher identified a path-traversal flaw in Azure Resource Manager DynamicInvoke for Azure Logic Apps API Connections. Encoded dot-dot segments could direct requests to another tenant's connection, with a proof of concept reading a secret through a victim-connected Azure Key Vault.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.