Junglewise Threat Intelligence

CVE-2026-40381: Microsoft Azure Connected Machine Agent privilege escalation

CVE-2026-40381 · Severity: high · CVSS 7.8 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

The Azure Connected Machine Agent, which manages non-Azure servers for use with Azure services, contains a security flaw in how it manages permissions. An attacker who already has low-level access to a server could exploit this to gain full administrative control over the machine. This could lead to unauthorized data access, system-wide changes, or the disruption of critical services.

Technical details

An improper access control vulnerability (CWE-284) exists in the Microsoft Azure Connected Machine Agent. The flaw allows a local attacker with low-privileged user access to bypass security restrictions and elevate their privileges to a higher level, such as SYSTEM or root. The attack vector is local, requiring the attacker to already have an authenticated session on the target host. Successful exploitation grants the attacker full confidentiality, integrity, and availability impact over the affected system. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Azure Connected Machine Agent

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References