Executive brief
Azure Arc is Microsoft's service for managing hybrid cloud infrastructure across on-premises and cloud environments. A misconfiguration in its cross-domain access policies allows attackers on the network to bypass authentication controls and gain elevated privileges, potentially compromising the entire hybrid infrastructure under management.
Technical details
The vulnerability stems from a permissive cross-domain policy that fails to properly validate or restrict access to untrusted domains within Azure Arc. An attacker with network access can exploit this configuration to bypass authentication mechanisms and escalate privileges. The vulnerability is remotely exploitable over the network without requiring prior authentication or user interaction. Successful exploitation grants an attacker elevated permissions that can be leveraged to compromise systems and data managed by Azure Arc. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Azure Arc
Timeline
- 2026-09-08: disclosed