CVE-2026-81349
Microsoft · Published September 8, 2026
7.2
CVSS v3.1
HIGHPatch availableGet patch
Description
Azure HDInsight Ambari Elevation of Privilege Vulnerability. Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Affected Products
- Azure HDInsight
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C