Junglewise Threat Intelligence

CVE-2026-26147: Microsoft Azure Compute Gallery information disclosure via improper input validation

CVE-2026-26147 · Severity: high · CVSS 7.7 · Published 2026-05-22

Vendors: Microsoft.

Executive brief

Microsoft Azure Compute Gallery, a service used to manage and share virtual machine images, contains a security vulnerability that could lead to unauthorized data exposure. An attacker with basic user access to the network can exploit this flaw to view sensitive information they are not authorized to see. This could potentially compromise proprietary system configurations or internal data stored within the gallery.

Technical details

A vulnerability exists in Microsoft Azure Compute Gallery due to improper input validation (CWE-20). An authenticated attacker with low-level privileges can exploit this flaw over the network without any user interaction. By sending specially crafted requests to the service, the attacker can bypass intended access controls to disclose sensitive information. The vulnerability has been assigned a CVSS score of 7.7, reflecting a high impact on confidentiality with a scope change, indicating the attacker may access data beyond the immediate security scope of the affected component. As this is an exclusively hosted service, Microsoft typically manages the backend updates.

Affected products

  • Microsoft Azure Compute Gallery

Timeline

  • 2026-05-22: advisory: Initial advisory published by Microsoft and NVD.

References