CyberICT

CVE-2026-40381

Microsoft · Published May 12, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Azure Connected Machine Agent Elevation of Privilege Vulnerability. Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Affected Products

  • Azure Connected Machine Agent

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C