


Perceptive Security
SOC/SIEM Consultancy

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
Published:
2 april 2026 om 22:00:00
Alert date:
3 april 2026 om 17:05:03
Source:
nvd.nist.gov
Cloud & Virtualization
A server-side request forgery (SSRF) vulnerability has been identified in Azure Custom Locations Resource Provider (RP). The vulnerability allows an authorized attacker to elevate privileges over a network. This affects Microsoft Azure's Custom Locations service, which is part of Azure's resource management infrastructure. The vulnerability requires the attacker to already have authorized access, but enables privilege escalation within the network environment. Given the cloud infrastructure nature and privilege escalation capability, this represents a significant security concern for Azure environments.
Technical details
Mitigation steps:
Affected products:
Azure Custom Locations Resource Provider
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-26135
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26135
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
