critical · CVSS v3 10
CVE-2026-69399
CVE-2026-69399 is an elevation‑of‑privilege flaw in Azure Arc that allows an attacker with limited access to gain higher privileges on the t
Overview
CVE-2026-69399 is an elevation‑of‑privilege flaw in Azure Arc that allows an attacker with limited access to gain higher privileges on the target system. The vulnerability is exploitable through misconfigured role‑based access controls and can lead to full control over Azure‑connected resources. It is critical because it bypasses normal security boundaries without requiring additional credentials.
Description
Azure Arc Elevation of Privilege Vulnerability
Impact
The flaw compromises Confidentiality, Integrity, and Availability of Azure‑connected resources by allowing an attacker to elevate privileges and execute arbitrary commands. Defenders are impacted because compromised accounts can modify or delete data, tamper with configurations, and disrupt services. The attack surface extends to any environment where Azure Arc is used to manage on‑premises or multi‑cloud resources.
Remediation
['Apply the latest Azure Arc security patch or update to the most recent release immediately.', 'Review and tighten RBAC assignments, ensuring least‑privilege for all users and service principals.', 'Enable Azure Policy to enforce minimum privilege levels for Azure Arc‑enabled resources.', 'Monitor privileged account activity with Azure Monitor and Azure Sentinel for anomalous behavior.', 'Disable or restrict any unused Azure Arc connectors and services that are not required for operations.']
Risk context
With a CVSS v3 score of 10.0, this vulnerability is classified as critical and requires urgent attention. No EPSS data is available, but the high severity and potential for full system compromise demand immediate patching and hardening.
Affected products
- Azure Arc
- Azure Arc‑enabled servers
- Azure Arc‑enabled Kubernetes
- Azure Arc‑enabled data services
- Azure Arc‑enabled SQL
- Azure Arc‑enabled PostgreSQL
- Azure Arc‑enabled MySQL
- Azure Arc‑enabled Redis
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 10
- CVSS v4
- —
- EPSS
- —