Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-24306. PoCs published by ExploreUnknowed.
AI-analyzed exploit summary This PoC demonstrates a privilege escalation vulnerability in Azure Front Door (CVE-2026-24306), allowing arbitrary routing rule injection, backend pool modification, and WAF policy override via header reflection and malformed rule priority collisions.
Description
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Exploits (1)
This PoC demonstrates a privilege escalation vulnerability in Azure Front Door (CVE-2026-24306), allowing arbitrary routing rule injection, backend pool modification, and WAF policy override via header reflection and malformed rule priority collisions.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H