CVE-2026-32171 is a privilege escalation vulnerability in Azure Logic Apps stemming from insufficiently protected credentials, allowing authenticated attackers to escalate their privileges over a network. The vulnerability affects Azure Logic Apps deployments and poses a significant risk to organizations leveraging this platform for workflow automation and integration. With a CVSS score of 8.8 (HIGH), this vulnerability is characterized by a network attack vector, low complexity, and requires low privileges, enabling attackers with valid credentials to cause high-impact damage across confidentiality, integrity, and availability. The vulnerability currently shows minimal exploitation activity, with no known public exploit code or active inclusion on security watch lists, though the FAUCET Risk Score of 51.0 suggests moderate attention from the security community. Organizations should prioritize patching and implementing compensating controls around credential management and access governance, particularly for privileged users within Logic Apps environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_logic_apps:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.