Description
Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, gain privileges, obtain sensitive information.
Below is a complete list of vulnerabilities:
- An elevation of privilege vulnerability in Application Insights Profiler can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure Active Directory can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Azure Logic Apps can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Azure SQL Database can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Entra Provisioning Service can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure SRE Agent can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft 365 Admin Center can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Purview eDiscovery can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Azure Confidential Ledger can be exploited remotely to execute arbitrary code.
Original advisories
- CVE-2026-50481
- CVE-2026-56161
- CVE-2026-56162
- CVE-2026-59115
- CVE-2026-62830
- CVE-2026-62873
- CVE-2026-65668
- CVE-2026-68823
Exploitation
Related products
CVE list
- CVE-2026-49163 unknown
- CVE-2026-50481 unknown
- CVE-2026-56161 unknown
- CVE-2026-56162 unknown
- CVE-2026-59115 unknown
- CVE-2026-62830 unknown
- CVE-2026-62873 unknown
- CVE-2026-65668 unknown
- CVE-2026-68823 unknown
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!