Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-69399: Azure Arc may let attackers gain higher privileges

CVE-2026-69399 · published 22 days ago
Summary

The Azure Arc service could be tricked into giving a user more access than intended. This could allow an attacker to control or change settings in your connected systems. Install the latest updates from Microsoft and review your access controls to lower the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft azure arc -
microsoft azure_arc All versions
cpe:2.3:a:microsoft:azure_arc:-:*:*:*:*:*:*:*
Original advisory text
Azure Arc Elevation of Privilege Vulnerability
Azure Arc Elevation of Privilege Vulnerability
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-69399 · MITRE
Track software like this
Free during beta