CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-56161

criticalCVSS 9.6covered by 1 sourcefirst seen 2026-08-06
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

CSIRTS triage

What
Improper access control allows disclosure of information through the service.
Who is affected
All Azure Logic Apps deployments accessible to authorized attackers are affected.
Urgency
Critical severity (CVSS 9.6) with no current exploitation reported; immediate access control review required.
Action
Review and restrict access controls in Azure Logic Apps deployments and apply vendor patches.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-56161

Get an email if CVE-2026-56161 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-56161

CVE.org record

Embed the live status

CVE-2026-56161 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-56161 status](https://www.csirts.com/badge/CVE-2026-56161)](https://www.csirts.com/cve/CVE-2026-56161)