Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

Azure Arc: Authorized access can be used to gain local admin rights

CVE-2026-26141
Summary

If not configured properly, Azure Arc can allow authorized users to gain local administrator privileges on servers, potentially leading to unauthorized access and data modification. This issue affects Azure Arc users who have not set up proper authentication controls. To protect against this, ensure Azure Arc is configured with strict access controls and multi-factor authentication is enabled.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
microsoft azure_automation_hybrid_worker_windows_extension > 1.0.0 , <= 1.3.74 –
Original title
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Original description
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
nvd CVSS3.1 7.8
Vulnerability type
CWE-287 Improper Authentication
CWE-863 Incorrect Authorization
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026