A vulnerability labeled as critical has been found in Microsoft Azure Custom Locations Resource Provider. This vulnerability affects unknown code. The manipulation results in server-side request forgery.

This vulnerability is known as CVE-2026-26135. It is possible to launch the attack remotely. No exploit is available.

This product is a managed service, indicating that users are not permitted to maintain vulnerability countermeasures themselves.