CVE-2026-40381
Microsoft · Published May 12, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Azure Connected Machine Agent Elevation of Privilege Vulnerability. Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Affected Products
- Azure Connected Machine Agent
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C