Junglewise Threat Intelligence

CVE-2026-69555: Microsoft Azure Arc privilege escalation via incorrect authorization

CVE-2026-69555 · Severity: critical · CVSS 10 · Published 2026-08-20

Technologies: Microsoft Azure Arc. Vendors: Microsoft.

Executive brief

Azure Arc is Microsoft's service for managing hybrid and multi-cloud infrastructure. A critical authorization flaw allows an unauthenticated attacker on the network to gain elevated privileges and take control of Arc-managed systems. This could enable an attacker to compromise servers, applications, and data across an organization's entire hybrid cloud environment.

Technical details

Azure Arc contains an incorrect authorization vulnerability that allows an unauthenticated network-based attacker to escalate privileges. The vulnerability results from improper authorization checks in the Arc service, enabling an attacker to bypass authentication and access controls over the network. An attacker can exploit this to gain elevated privileges and gain unauthorized control over Arc-connected resources. The issue affects multiple versions of Azure Arc. A patch is available from Microsoft.

Affected products

  • Microsoft Azure Arc

Timeline

  • 2026-08-20: disclosed

References

Related threats