CyberICT

CVE-2026-81349

Microsoft · Published September 8, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Azure HDInsight Ambari Elevation of Privilege Vulnerability. Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.

Affected Products

  • Azure HDInsight

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C