H3-2026-0060¶
Azure App Service Code Execution via Kudu API
| Category | VULNERABILITY |
| Base Score | 8.5 |
Description¶
Azure App Services expose a Kudu SCM API (https://
Impact¶
Attackers with Azure management API credentials or publishing credentials can execute arbitrary commands in the App Service container, steal managed identity tokens to move laterally across Azure resources, and exfiltrate application secrets including database connection strings and API keys stored as app settings.