CVE-2026-69555
published 2026-08-20CVE-2026-69555: Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
PriorityP266critical10CVSS 3.1
AVNACLPRNUINSCCHIHAN
EPSS
0.44%
37.8th percentile
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_arc | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Azure Arc improper authorization
vuldb·2026-08-21·CVSS 10.0
CVE-2026-69555 [CRITICAL] Microsoft Azure Arc improper authorization
A vulnerability was found in Microsoft Azure Arc. It has been classified as critical. This impacts an unknown function. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-69555. The attack is possible to be carried out remotely. No exploit exists.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
GHSA
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
ghsa_unreviewed·2026-08-21
CVE-2026-69555 [CRITICAL] CWE-863 Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
No detection rules found.
No public exploits indexed.
2026-08-20
Published