CyberICT

CVE-2026-42822

Microsoft · Published May 18, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability. Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • Azure Local

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C