Junglewise Threat Intelligence

CVE-2026-70009: Microsoft Azure Arc path traversal privilege escalation

CVE-2026-70009 · Severity: critical · CVSS 9.3 · Published 2026-09-17

Technologies: Microsoft Azure Arc. Vendors: Microsoft.

Executive brief

Azure Arc is Microsoft's service for managing on-premises and multi-cloud infrastructure. A path traversal vulnerability allows an attacker on the network to escalate privileges on systems running Azure Arc, potentially gaining administrative control and access to sensitive data across connected infrastructure.

Technical details

A path traversal flaw in Azure Arc fails to properly validate or restrict file paths, enabling an unauthenticated attacker to traverse restricted directories and execute privileged operations over the network. The vulnerability allows direct privilege escalation without requiring prior authentication or user interaction, making it a high-impact issue for organizations using Azure Arc for infrastructure management.

Affected products

  • Microsoft Azure Arc

Timeline

  • 2026-09-17: disclosed

References

Related threats