Executive Summary

The Microsoft Security Response Center (MSRC) has issued a high-severity security advisory detailing an authentication and identity impersonation vulnerability within Azure Container Apps (ACA) environments utilizing the integrated Distributed Application Runtime (Dapr). Tracked under CVE-2026-58204, the flaw carries a CVSS v3.1 base score of 8.5 (High) and impacted microservice applications running across managed Azure Kubernetes infrastructure.

Dapr provides microservices with standardized APIs for service-to-service invocation, state management, and pub/sub messaging through a dedicated sidecar proxy running alongside each application container. The flaw allowed an attacker who had compromised a single front-end container to forge caller identity headers and invoke backend administrative APIs without valid mutual TLS credentials.

Technical Root Cause: Header Injection via Dapr App-ID Forwarding

When a container initiates an inter-service request through Dapr, it sends an HTTP request to its local sidecar (http://localhost:3500/v1.0/invoke/<app-id>/method/<endpoint>). The sidecar verifies the caller's identity and attaches cryptographic SPIFFE ID claims and an internal dapr-caller-app-id header before forwarding the traffic across the mesh via encrypted mTLS.

Security researchers discovered that the Dapr sidecar ingress filter failed to sanitize incoming client headers if the client explicitly submitted a pre-populated dapr-caller-app-id header in its local loopback request. The sidecar forwarded the spoofed header unchanged to the destination service, tricking backend authorization middleware into believing the request originated from an internal administrative microservice (e.g., billing-core or order-processor).

# Vulnerable invocation demonstrating header spoofing
curl -X POST http://localhost:3500/v1.0/invoke/finance-service/method/execute-transfer   -H "Content-Type: application/json"   -H "dapr-caller-app-id: finance-admin"   -d '{"account_id": "ACC-9921", "amount": 50000}'
# Backend accepted request believing caller was authenticated finance-admin

Cloud Blast Radius & Lateral Movement

In modern cloud-native architectures, enterprises rely on internal microservice trust boundaries to protect sensitive backend data stores. Successful exploitation allowed threat actors to:

  • Pivot from an untrusted public-facing web microservice directly into restricted internal payment and data management microservices.
  • Query Dapr state stores (such as Azure Cosmos DB and Redis caches) under privileged service identities, exfiltrating encrypted customer records.
  • Publish unauthorized messages to enterprise service buses and Kafka topics, corrupting operational event streams.

Remediation Actions & Guidance for Azure Customers

Microsoft deployed automated platform updates across all public and sovereign cloud regions, patching the managed ACA control plane and sidecar injection templates. Cloud architects managing ACA environments should verify the following configurations:

  1. Verify Dapr Sidecar Revision: Ensure all running container app environments are executing Dapr runtime version 1.14.2 or higher:
    az containerapp env show --name production-env --resource-group cloud-rg --query "properties.daprConfiguration.version"
  2. Enforce App-Level Authentication Tokens: Configure Dapr API token authentication (DAPR_API_TOKEN) to require explicit shared secret validation for all local loopback API invocations.
  3. Implement Fine-Grained Access Control Policies: Deploy Dapr access control policies (ACLs) defining explicit whitelists of permitted service invocation paths between microservice app-IDs.