CyberICT

CVE-2026-26117

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability. Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Affected Products

  • Arc Enabled Servers - Azure Connected Machine Agent

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C