External risk intelligence

Azure Logic Apps Path Traversal Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-70200

Azure Logic Apps are commonly deployed as internet-facing cloud services, APIs, and automated integration workflows that frequently interact with external network traffic and web-based endpoints.

Path Traversal

Microsoft Azure Logic Apps

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An issue has been identified in Azure Logic Apps that could allow an unauthorized attacker to gain elevated privileges through network access. This vulnerability stems from an improper limitation in how file paths are handled, potentially enabling unauthorized access to restricted directories.

  • Unauthorized access to restricted directories.
  • Confirms potential for privilege escalation.
  • Verify relevance and exposure to Azure Logic Apps.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network requests to Azure Logic Apps. This could allow them to access and potentially modify sensitive files or resources that they should not have access to.

  • Network-accessible entry point.
  • Path traversal in Logic Apps.
  • Unauthorized privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthorized attacker to elevate privileges over a network by exploiting an improper limitation of a pathname to a restricted directory in Azure Logic Apps. When supported, this could affect the integrity and availability of the Logic App service and potentially lead to unauthorized access to sensitive information or system control.

  • Azure Logic App service integrity and availability.
  • Exploiting path traversal via network requests.
  • Unauthorized privilege escalation and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

For Azure Logic Apps, ownership typically falls to the cloud platform or infrastructure teams managing the Azure environment, potentially with application owners if specific workflows are impacted. The first practical step is to identify all Azure Logic App instances, determine their network exposure and business criticality, and then map them to their respective owners to prioritize remediation efforts.

  • Platform or application owners should manage the issue.
  • Verify Azure Logic Apps' network exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Azure Logic Apps?

Azure Logic Apps is a cloud-based platform-as-a-service designed to automate workflows and integrate apps, data, and services across enterprises. It allows developers to create automated tasks that execute logic and connect disparate systems without writing complex code, often serving as the connective tissue for cloud environments.

What does path traversal mean in CVE-2026-70200?

Path traversal, or CWE-22, is a weakness where software fails to properly sanitize user input used in file path construction. In this CVE, it allows an unauthorized party to manipulate input to access restricted directories or files outside the intended scope, which can lead to privilege escalation.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted network requests to the target Logic App. The vulnerability requires network-accessible entry points to process these malicious paths. It is not triggered by internal administrative console configurations or non-network-facing background tasks that do not accept external file-path input.

Is my environment at risk for CVE-2026-70200?

Halo Surface Signal indicates that Azure Logic Apps are commonly deployed as internet-facing services or APIs, increasing the likelihood of exposure. You should evaluate any Logic App that processes requests from external networks, as these are primary candidates for network-based interaction.

How do I respond to this vulnerability?

Start by identifying all instances of Azure Logic Apps within your environment. Document which workflows are business-critical and assess their network exposure. Coordinate with your cloud platform team to verify ownership and ensure you are positioned to apply updates or configuration changes as provided by the vendor.

References