Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32171

29
FAUCET Score

CVE-2026-32171 is a privilege escalation vulnerability in Azure Logic Apps stemming from insufficiently protected credentials, allowing authenticated attackers to escalate their privileges over a network. The vulnerability affects Azure Logic Apps deployments and poses a significant risk to organizations leveraging this platform for workflow automation and integration. With a CVSS score of 8.8 (HIGH), this vulnerability is characterized by a network attack vector, low complexity, and requires low privileges, enabling attackers with valid credentials to cause high-impact damage across confidentiality, integrity, and availability. The vulnerability currently shows minimal exploitation activity, with no known public exploit code or active inclusion on security watch lists, though the FAUCET Risk Score of 51.0 suggests moderate attention from the security community. Organizations should prioritize patching and implementing compensating controls around credential management and access governance, particularly for privileged users within Logic Apps environments.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:microsoft:azure_logic_apps:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
36.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 24th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-32171Important

Azure Logic Apps Elevation of Privilege Vulnerability

Apr 14, 2026

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2026-32171
Vendor Advisory