Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-58630: Azure App Service: Unauthorized Privilege Elevation Over Network
CVE-2026-58630 · published 2 months ago
Summary
An unauthorized attacker can gain elevated access to Azure App Service over a network. This is a security risk because an attacker could potentially make unauthorized changes to the service or access sensitive data. To mitigate this risk, ensure that Azure App Service is properly configured with secure access controls and that users only have the necessary privileges to perform their tasks.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | azure app service for linux | - |
| microsoft | azure_app_service_for_linux |
All versions
cpe:2.3:a:microsoft:azure_app_service_for_linux:-:*:*:*:*:*:*:* |
Original advisory text
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published24 Jul 2026
Updated27 Sep 2026
First seen24 Jul 2026
Track software like this
Free during beta