Incorrect Authorization in Microsoft Azure Arc Enables Network Privilege Escalation
AI analysis
Microsoft Azure Arc, the service used to manage on-premises and multi-cloud servers from Azure, contains an incorrect authorization flaw (CWE-863) in which permission checks fail to properly restrict what an unauthorized party may do. Per the CVSS vector, the flaw is exploitable over a network with no privileges or user interaction required, and exploitation changes the security scope, allowing an unauthorized attacker to elevate privileges with high impact on confidentiality and integrity. Any organization that has enrolled servers or other resources with Azure Arc is potentially exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only about a 0.4% probability of exploitation within 30 days.
What to do: Apply Microsoft's fix as soon as it is released (expected with the September 2026 Patch Tuesday updates) and check Microsoft's advisory for affected Azure Arc components and agent versions. Until then, review and minimize permissions granted to Arc-enabled resources and restrict network reachability to Arc management endpoints. Monitor Microsoft's advisories for updated agent packages and redeploy them promptly to enrolled servers.
Estimated exposure
mass≈1M+ Arc-enabled servers (Azure Arc is Microsoft's broadly deployed hybrid/multi-cloud management service) — Azure Arc is Microsoft's management plane for hybrid and multi-cloud server estates and is widely deployed across large enterprises, so the installed base of enrolled servers plausibly reaches into the millions, making this a mass-scale…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.