CVE-2026-24306

CRITICAL

Azure Front Door - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-24306. PoCs published by ExploreUnknowed.

AI-analyzed exploit summary This PoC demonstrates a privilege escalation vulnerability in Azure Front Door (CVE-2026-24306), allowing arbitrary routing rule injection, backend pool modification, and WAF policy override via header reflection and malformed rule priority collisions.

Description

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.

Exploits (1)

nomisec WORKING POC
by ExploreUnknowed · poc
https://github.com/ExploreUnknowed/CVE-2026-24306

This PoC demonstrates a privilege escalation vulnerability in Azure Front Door (CVE-2026-24306), allowing arbitrary routing rule injection, backend pool modification, and WAF policy override via header reflection and malformed rule priority collisions.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Azure Front Door Standard & Premium tiers (pre-patch builds before 2026-01-22)
No auth needed
Prerequisites: Public endpoint exposure · Valid Azure resource ID format
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0009
EPSS Percentile 26.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (2)
Microsoft/Azure Front Door -
microsoft/azure_front_door
Published Jan 22, 2026
Tracked Since Feb 18, 2026