CVE-2026-26141
Microsoft · Published March 10, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability. Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Affected Products
- Azure Automation Hybrid Worker Windows Extension
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C