Microsoft has disclosed CVE-2026-56161, a critical (CVSS 9.6) improper access control flaw in Azure Logic Apps that allows an authorized attacker to disclose information over a network.
What Is It
CVE-2026-56161 is an improper access control vulnerability (CWE-284) in Microsoft Azure Logic Apps. Per Microsoft's description, the flaw "allows an authorized attacker to disclose information over a network."
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, base score 9.6, rated CRITICAL. Breaking that down: the attack is reachable over the network, requires low attack complexity, requires only low privileges, and needs no user interaction. Scope is CHANGED, meaning the impact extends beyond the vulnerable component's security boundary; this is the primary reason the issue scores this high. Confidentiality and integrity impact are both HIGH; availability impact is NONE.
Note that the scored integrity impact goes beyond Microsoft's one-line summary, which describes only information disclosure. Microsoft has not published detail reconciling the two, so treat the vector's HIGH integrity rating as the more conservative basis for risk assessment.
Why It Matters
The combination of low required privileges, no user interaction, and a changed scope means any account with minimal standing access could potentially reach data beyond its own authorization boundary. The 9.6 base score reflects that blast radius rather than the difficulty of the attack.
Microsoft has tagged this CVE as exclusively-hosted-service, indicating the affected component is a Microsoft-operated cloud service rather than customer-installed software.
CISA KEV status: As of 2026-08-06, CVE-2026-56161 does not appear in the CISA Known Exploited Vulnerabilities catalog, and neither Microsoft nor CISA has published confirmation of active exploitation.
What's Vulnerable
- Vendor: Microsoft
- Product: Azure Logic Apps
- Affected versions: listed as
-(no discrete version enumeration), consistent with a hosted service - CPEs: none published in the NVD record
Patch Status
Neither the NVD record nor Microsoft's published advisory data carries remediation guidance, a patch identifier, or a required-action deadline as of 2026-08-06. The CVE record is newly published and carries a vulnerability status of Received, meaning NVD analysis is not yet complete. Because the exclusively-hosted-service tag indicates a Microsoft-managed service, remediation is expected to be applied service-side by Microsoft; refer to the MSRC update guide below for the authoritative fix status.
Sources
- NVD, CVE-2026-56161 (source identifier: [email protected]): https://nvd.nist.gov/vuln/detail/CVE-2026-56161
- Microsoft MSRC Update Guide; CVE-2026-56161: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56161
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog