Junglewise Threat Intelligence

CVE-2026-81349: Microsoft Azure HDInsights OS command injection

CVE-2026-81349 · Severity: high · CVSS 7.2 · Published 2026-09-08

Executive brief

Azure HDInsights is a managed big data analytics service used for processing large datasets in the cloud. An OS command injection vulnerability allows an authorized user to execute arbitrary system commands with elevated privileges on the HDInsights cluster, potentially compromising data processing operations and gaining unauthorized access to sensitive analytics data.

Technical details

The vulnerability is an improper neutralization of special elements used in an OS command (CWE-78: OS Command Injection) in Azure HDInsights. An authenticated attacker can craft malicious input that is not properly sanitized before being passed to system command execution, allowing arbitrary command injection. The attack requires network access and prior authorization to the HDInsights service. A successful exploit enables privilege escalation and arbitrary code execution on the affected cluster nodes.

Affected products

  • Microsoft Azure HDInsights

Timeline

  • 2026-09-08: disclosed

References