Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-69399: Azure Arc may let attackers gain higher privileges
CVE-2026-69399 · published 22 days ago
Summary
The Azure Arc service could be tricked into giving a user more access than intended. This could allow an attacker to control or change settings in your connected systems. Install the latest updates from Microsoft and review your access controls to lower the risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | azure arc | - |
| microsoft | azure_arc |
All versions
cpe:2.3:a:microsoft:azure_arc:-:*:*:*:*:*:*:* |
Original advisory text
Azure Arc Elevation of Privilege Vulnerability
Azure Arc Elevation of Privilege Vulnerability
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-441Unintended Proxy or Intermediary ('Confused Deputy')
Timeline
Published17 Sep 2026
Updated9 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta