Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
The vulnerability classified as CWE-306 (Missing Authentication for Critical Function) means that critical functionality of Azure MCP Server is accessible without any authentication mechanism. An attacker remotely, over the network, without possessing an account or privileges and without user interaction, can invoke this function and gain access to protected data. The network attack vector (AV:N) with no privilege requirements (PR:N) and no interaction (UI:N) means that the exploit can be conducted entirely remotely and automatically.
An attacker can gain unauthorized access to sensitive information processed or stored by Azure MCP Server and perform unauthorized data modifications (High Integrity impact). Data confidentiality and integrity are severely compromised.
Apply patches available from the vendor in accordance with references published in the Microsoft Security Response Center (MSRC): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32211
Microsoft Azure Web Apps — Azure MCP Server; versions specified in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Azure Web Apps
APPMicrosoftall versions
Related vulnerabilities
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileg...
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate pri...
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server