🟠 High | Source: Microsoft Security Response Center
A path traversal vulnerability in Azure Application Insights Profiler allows an already-authenticated attacker to escalate their privileges over a network. The flaw arises from insufficient restrictions on file path inputs, potentially enabling access to resources beyond the intended scope. Although exploitation requires prior authorisation, the privilege escalation capability makes this a meaningful risk in shared or multi-tenant environments.
Security Architect’s Take: Review who has authorised access to Application Insights Profiler within your Azure subscriptions and apply the latest patch immediately. Consider enforcing least-privilege RBAC assignments and auditing Profiler activity logs for any anomalous access patterns whilst remediation is rolled out.
Original advisory: CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability