CVE-2026-26117
Microsoft · Published March 10, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability. Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
Affected Products
- Arc Enabled Servers - Azure Connected Machine Agent
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C