Executive brief
Azure Arc is Microsoft's service for managing hybrid and multi-cloud infrastructure. A critical authorization flaw allows an unauthenticated attacker on the network to gain elevated privileges and take control of Arc-managed systems. This could enable an attacker to compromise servers, applications, and data across an organization's entire hybrid cloud environment.
Technical details
Azure Arc contains an incorrect authorization vulnerability that allows an unauthenticated network-based attacker to escalate privileges. The vulnerability results from improper authorization checks in the Arc service, enabling an attacker to bypass authentication and access controls over the network. An attacker can exploit this to gain elevated privileges and gain unauthorized control over Arc-connected resources. The issue affects multiple versions of Azure Arc. A patch is available from Microsoft.
Affected products
- Microsoft Azure Arc
Timeline
- 2026-08-20: disclosed