rootpwn

critical · CVSS v3 10

CVE-2026-69399

CVE-2026-69399 is an elevation‑of‑privilege flaw in Azure Arc that allows an attacker with limited access to gain higher privileges on the t

Overview

CVE-2026-69399 is an elevation‑of‑privilege flaw in Azure Arc that allows an attacker with limited access to gain higher privileges on the target system. The vulnerability is exploitable through misconfigured role‑based access controls and can lead to full control over Azure‑connected resources. It is critical because it bypasses normal security boundaries without requiring additional credentials.

Description

Azure Arc Elevation of Privilege Vulnerability

Impact

The flaw compromises Confidentiality, Integrity, and Availability of Azure‑connected resources by allowing an attacker to elevate privileges and execute arbitrary commands. Defenders are impacted because compromised accounts can modify or delete data, tamper with configurations, and disrupt services. The attack surface extends to any environment where Azure Arc is used to manage on‑premises or multi‑cloud resources.

Remediation

['Apply the latest Azure Arc security patch or update to the most recent release immediately.', 'Review and tighten RBAC assignments, ensuring least‑privilege for all users and service principals.', 'Enable Azure Policy to enforce minimum privilege levels for Azure Arc‑enabled resources.', 'Monitor privileged account activity with Azure Monitor and Azure Sentinel for anomalous behavior.', 'Disable or restrict any unused Azure Arc connectors and services that are not required for operations.']

Risk context

With a CVSS v3 score of 10.0, this vulnerability is classified as critical and requires urgent attention. No EPSS data is available, but the high severity and potential for full system compromise demand immediate patching and hardening.

Affected products

  • Azure Arc
  • Azure Arc‑enabled servers
  • Azure Arc‑enabled Kubernetes
  • Azure Arc‑enabled data services
  • Azure Arc‑enabled SQL
  • Azure Arc‑enabled PostgreSQL
  • Azure Arc‑enabled MySQL
  • Azure Arc‑enabled Redis

Scores

Severity
critical
CVSS v2
10
CVSS v3
10
CVSS v4
EPSS

Azure Arc Elevation of Privilege Critical RBAC Patch Privileged Access Azure Security

← All CVEs