VDB

CVE-2026-21227

CVE-2026-21227 PUBLISHED CVSS 8.199999809265137 HIGH

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

EPSS 0.20% · 41.8th percentile

Risk Scores

CVSS v3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C
EPSS Score
0.20%
41.8th percentile

Affected Products

VendorProductVersions
microsoftazure_logic_apps*, -
MicrosoftAzure Logic Apps-, -

Timeline

  • Jan 13, 2026 CVE Published
  • Jan 22, 2026 PoC Published
  • Jan 23, 2026 EPSS Score
  • Jan 23, 2026 CVE Updated
  • Jan 23, 2026 PoC Published
  • Jan 23, 2026 PoC Published
  • Jan 23, 2026 PoC Published
  • Jan 26, 2026 EPSS Score
  • Jan 28, 2026 EPSS Score
  • Jan 31, 2026 EPSS Score
  • Feb 2, 2026 EPSS Score
  • Feb 5, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›