ZeroHour

CVE-2026-81349

moderate

OS Command Injection Privilege Elevation in Microsoft Azure HDInsights

CVSS 3.1
7.2 high
EPSS
<1%p52
Published
()
Modified
AI analysis

CVE-2026-81349 is an operating-system command injection flaw (CWE-78) in Microsoft's Azure HDInsights managed big-data service. It is triggered when the service improperly neutralizes special elements passed into an OS command, and per the CVSS vector an attacker must already hold high-level authorized access, exploiting it over the network with no user interaction required. Successful exploitation allows the attacker to elevate privileges, with high impact on the confidentiality, integrity, and availability of the affected HDInsight environment. Only organizations running Azure HDInsight clusters are affected; the flaw was fixed as part of Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws. No public proof-of-concept is known, it is not listed in CISA's KEV catalog, and EPSS estimates roughly a 0.7% chance of exploitation within 30 days.

What to do: Review Microsoft's September 2026 Patch Tuesday advisory for CVE-2026-81349 and apply any required service updates or customer actions to HDInsight clusters as directed. Because exploitation requires an already highly privileged authorized attacker, audit and restrict highly privileged roles, service principals, and identities with access to HDInsight resources. Monitor Azure Service Health and the MSRC advisory page for service-side remediation details.

Affected
Microsoft Azure HDInsights
Estimated exposure
moderatelikely on the order of low tens of thousands of Azure HDInsight clusters worldwide (exact counts unpublished) — Azure HDInsights is a specialized managed Hadoop/Spark/Kafka service used only by Azure customers with big-data workloads and Microsoft publishes no cluster counts, so this order-of-magnitude figure is inferred from its enterprise-only,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

Patch Tuesday - September 2026

Microsoft's September 2026 Patch Tuesday fixes 999 CVEs, a record, with two zero-day privilege escalation flaws already exploited in the wild.

Microsoft published 974 own-product vulnerabilities plus 25 non-Microsoft CVEs, totaling 999 — the most CVEs Microsoft has ever released in a single day. Two flaws are exploited in the wild: CVE-2026-85880, an out-of-bounds write in Windows ALPC granting SYSTEM privileges, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack also leading to SYSTEM. Chrome's V8 zero-day CVE-2026-85046 was patched in Edge on September 2, but Microsoft had not published a corresponding advisory, leaving uncertainty about other Chromium fixes in Edge. October 14 lifecycle changes end servicing for Windows 11 24H2 Home/Pro, Office 2021, and Exchange Server 2016/2019.

Rapid7 Blog · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-85046+10 CVEs

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1