Azure Functions
by Microsoft
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36052 | Hig | 0.58 | 8.6 | 0.22 | Nov 14, 2023 | Azure CLI REST Command Information Disclosure Vulnerability | ||
| CVE-2024-49052 | Hig | 0.53 | 8.2 | 0.01 | Nov 26, 2024 | Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-33074 | Hig | 0.49 | 7.5 | 0.01 | Apr 30, 2025 | Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. | ||
| CVE-2024-38204 | Hig | 0.49 | 7.5 | 0.01 | Oct 15, 2024 | Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2020-16904 | Med | 0.35 | 5.3 | 0.03 | Oct 16, 2020 | An elevation of privilege vulnerability exists in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. This security update addresses… | ||
| CVE-2026-21532 | 0.00 | — | 0.01 | Feb 5, 2026 | Azure Function Information Disclosure Vulnerability |
- risk 0.58cvss 8.6epss 0.22
Azure CLI REST Command Information Disclosure Vulnerability
- risk 0.53cvss 8.2epss 0.01
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.01
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
- risk 0.35cvss 5.3epss 0.03
An elevation of privilege vulnerability exists in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. This security update addresses…
- CVE-2026-21532Feb 5, 2026risk 0.00cvss —epss 0.01
Azure Function Information Disclosure Vulnerability