CyberICT

CVE-2026-26148

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability. External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

Affected Products

  • Microsoft Azure AD SSH Login extension for Linux

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C