CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56161: Azure Logic Apps Information Disclosure Vulnerability

criticalCVSS 9.6CVE-2026-56161
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CSIRTS triage

What
Improper access control allows disclosure of information through the service.
Who is affected
All Azure Logic Apps deployments accessible to authorized attackers are affected.
Urgency
Critical severity (CVSS 9.6) with no current exploitation reported; immediate access control review required.
Action
Review and restrict access controls in Azure Logic Apps deployments and apply vendor patches.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Azure Logic Apps

Get an email when a new Azure Logic Apps advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
critical — CVSS 9.6
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56161

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-56161coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center