A Norwegian security researcher on Thursday described five vulnerabilities in Microsoft Azure that let him seize other customers’ cloud connections and reach into their databases, key vaults and external services, flaws he said earned him $200,000 in bug bounties.

The weaknesses sit in API Connections, a part of Azure Logic Apps that links a customer’s apps to backend services such as Azure Key Vault, Azure SQL, Jira and Salesforce. Haakon Wik Gulbrandsrud, a security consultant with Binary Security, a Norwegian penetration-testing firm, wrote that the flaws allow “anyone to fully compromise any other connection worldwide, giving full access to the connected backend” — including across tenant boundaries, meaning one paying Azure customer could rummage through another’s. Dark Reading earlier reported on Mr. Gulbrandsrud’s first such finding.

The trouble is architectural. When a logic app calls a connected service, the request passes through a shared Azure API Management instance that swaps the caller’s token for the token configured on the backend connection. Because that shared service, reached through the Azure Resource Manager API, holds rights to every customer’s connections, an attacker who can aim it at a connection he does not own inherits the victim’s access. Mr. Gulbrandsrud has called the system “Azure’s weakest link” in a series of posts; Thursday’s was the latest installment. He also presented the work at the Blue Hat Asia 2026 conference.

His first cross-tenant compromise used an endpoint called DynamicInvoke and a basic path-traversal payload — a chain of “..” segments slipped into the request path — to make the shared service read a secret from a Key Vault belonging to a different tenant. The vault returned it. The secret’s value, in his demonstration: “dontreadme.”

Microsoft marked that vulnerability fixed, but the repair amounted to a blacklist on the path parameter rather than a change to who may act on whose connection. Mr. Gulbrandsrud then spun up a Standard Logic App, which gives a fully dedicated host, connected to it over SSH and pulled out the underlying code. There he found the fix. He also found something he was not looking for: undocumented sibling functions to DynamicInvoke, sitting along the same path, among them one called DynamicList. The blacklist covered DynamicInvoke only.

DynamicList took a more laborious payload — each path parameter had to be specified on its own — but the same traversal worked. In his demonstration he crossed into another tenant’s connection and ran an arbitrary query against the victim’s Azure SQL database, inserting a row he labeled “NewEvilSecrets.”

He reported the DynamicList case first, he wrote, in the hope that Microsoft would patch it the same piecemeal way and leave him more endpoints to report. It didn’t work out that way. “Sadly, their fix involved simply blocking all these endpoints,” he wrote. No other mitigations appear to be in place, he added, so if the endpoints ever become reachable again, they would presumably be exploitable.

There is one caveat, and Mr. Gulbrandsrud conceded it himself: customers can scope the tokens behind their connections to minimal privileges, which would limit what a hijacker inherits. He doubted many bother. For OAuth connections the token is inevitably that of the person who set the connection up, he wrote, and for API keys, “who cares enough to scope such things minimally? Microsoft doesn’t, at least.”

Five vulnerabilities, one conclusion. “In total,” he wrote, “the vulnerabilities here netted me a cool $200,000.”