🟠 High | Source: Microsoft Security Response Center
A vulnerability in Azure App Service on Azure Stack Hub allows an attacker with network access to gain elevated privileges without proper authorisation. The flaw stems from improper access controls, meaning an unauthenticated attacker could potentially take actions beyond their intended permissions. Organisations running Azure App Service on Azure Stack Hub should treat this as a priority remediation given the network-accessible attack vector.
Security Architect’s Take: Review your Azure Stack Hub deployments immediately and apply Microsoft’s patch as soon as it is available; in the interim, restrict network access to Azure App Service management endpoints using firewall rules or network segmentation to reduce exposure.
Original advisory: CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability