top of page
perceptive_background_267k.jpg

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

Published:

2 april 2026 om 22:00:00

Alert date:

3 april 2026 om 17:05:03

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization

A server-side request forgery (SSRF) vulnerability has been identified in Azure Custom Locations Resource Provider (RP). The vulnerability allows an authorized attacker to elevate privileges over a network. This affects Microsoft Azure's Custom Locations service, which is part of Azure's resource management infrastructure. The vulnerability requires the attacker to already have authorized access, but enables privilege escalation within the network environment. Given the cloud infrastructure nature and privilege escalation capability, this represents a significant security concern for Azure environments.

Technical details

Mitigation steps:

Affected products:

Azure Custom Locations Resource Provider

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page