ZeroHour

CVE-2026-69555

mass

Incorrect Authorization in Microsoft Azure Arc Enables Network Privilege Escalation

CVSS 3.1
10.0 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

Microsoft Azure Arc, the service used to manage on-premises and multi-cloud servers from Azure, contains an incorrect authorization flaw (CWE-863) in which permission checks fail to properly restrict what an unauthorized party may do. Per the CVSS vector, the flaw is exploitable over a network with no privileges or user interaction required, and exploitation changes the security scope, allowing an unauthorized attacker to elevate privileges with high impact on confidentiality and integrity. Any organization that has enrolled servers or other resources with Azure Arc is potentially exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS currently estimates only about a 0.4% probability of exploitation within 30 days.

What to do: Apply Microsoft's fix as soon as it is released (expected with the September 2026 Patch Tuesday updates) and check Microsoft's advisory for affected Azure Arc components and agent versions. Until then, review and minimize permissions granted to Arc-enabled resources and restrict network reachability to Arc management endpoints. Monitor Microsoft's advisories for updated agent packages and redeploy them promptly to enrolled servers.

Affected
Microsoft Azure Arc
Estimated exposure
mass≈1M+ Arc-enabled servers (Azure Arc is Microsoft's broadly deployed hybrid/multi-cloud management service) — Azure Arc is Microsoft's management plane for hybrid and multi-cloud server estates and is widely deployed across large enterprises, so the installed base of enrolled servers plausibly reaches into the millions, making this a mass-scale…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
azure arc
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.

This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.

Help Net Security · 6d agoAdvisory in the wildCVE-2026-55040CVE-2026-63520CVE-2026-62911+5 CVEs1