CVE-2026-26148
Microsoft · Published March 10, 2026
8.1
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability. External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
Affected Products
- Microsoft Azure AD SSH Login extension for Linux
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C