Junglewise Threat Intelligence

CVE-2026-62895: Microsoft Azure Arc cross-domain policy privilege escalation

CVE-2026-62895 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Azure Arc. Vendors: Microsoft.

Executive brief

Azure Arc is Microsoft's service for managing hybrid cloud infrastructure across on-premises and cloud environments. A misconfiguration in its cross-domain access policies allows attackers on the network to bypass authentication controls and gain elevated privileges, potentially compromising the entire hybrid infrastructure under management.

Technical details

The vulnerability stems from a permissive cross-domain policy that fails to properly validate or restrict access to untrusted domains within Azure Arc. An attacker with network access can exploit this configuration to bypass authentication mechanisms and escalate privileges. The vulnerability is remotely exploitable over the network without requiring prior authentication or user interaction. Successful exploitation grants an attacker elevated permissions that can be leveraged to compromise systems and data managed by Azure Arc. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Azure Arc

Timeline

  • 2026-09-08: disclosed

References

Related threats