CyberICT

CVE-2026-26141

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability. Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Affected Products

  • Azure Automation Hybrid Worker Windows Extension

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C