
Proof-of-concept exploit for Azure Front Door privilege escalation (CVE-2026-24306) enabling routing rule injection, backend pool modification, and WAF policy override on misconfigured instances.
Vulnerability allows:
Affected: Azure Front Door Standard & Premium tiers (pre-patch builds before 2026-01-22)
Exploitation requires only public endpoint exposure + valid Azure resource ID format. No subscription-level credentials needed in default vulnerable config.
Tested vectors:
Usage:
python poc.py --target https://target-frontend.azurefd.net --afd-id /subscriptions/xxxx/resourceGroups/rg/providers/Microsoft.Cdn/profiles/xxxx
Lab setup included (setup-lab.ps1 + Bicep).
Download:
Contact: @B1gh0rnn on X (DMs open).