CVE-2026-26135
Microsoft Azure Custom Locations Resource Provider, azure custom locations resource provider
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
- CVSS
- 8.8
- EPSS
- 0.60% 45.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.03