rootpwn

critical · CVSS v3 9.3

CVE-2026-70009

CVE‑2026‑70009 is a path‑traversal flaw in Azure Arc that lets an unauthenticated attacker gain elevated privileges over the network. The vu

Overview

CVE‑2026‑70009 is a path‑traversal flaw in Azure Arc that lets an unauthenticated attacker gain elevated privileges over the network. The vulnerability can be exploited to read or modify restricted files and execute arbitrary code on Azure‑Arc‑enabled hosts. It is rated critical with a CVSS v3 score of 9.3.

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Impact

The flaw compromises confidentiality, integrity, and availability of the affected hosts. An attacker can read or tamper with system files, execute code with elevated privileges, and potentially disrupt services or exfiltrate data. Azure Arc users running on-premises or hybrid workloads are directly impacted, as the vulnerability is exploitable over the network without local authentication.

Remediation

1. Apply the latest Microsoft patch or upgrade to the newest Azure Arc agent version. 2. Restrict network access to the Arc agent by using firewall rules or Azure Network Security Groups. 3. Enforce least‑privilege for Arc service principals and disable unused features. 4. Enable Azure Policy or Azure Security Center to monitor for abnormal file access or privilege escalation. 5. Conduct regular vulnerability scans and verify that the path‑traversal fix is in place.

Risk context

With a CVSS v3 score of 9.3 and no EPSS data, the vulnerability is considered highly urgent. Immediate patching and network hardening are recommended to mitigate the risk of privilege escalation and potential data compromise.

Affected products

  • Azure Arc
  • Azure Arc‑enabled servers
  • Azure Arc‑enabled Kubernetes
  • Azure Arc‑enabled data services
  • Azure Arc‑enabled SQL
  • Azure Arc‑enabled VMware
  • Azure Arc‑enabled GitHub
  • Azure Arc‑enabled Azure services

Scores

Severity
critical
CVSS v2
8.5
CVSS v3
9.3
CVSS v4
EPSS

path-traversal Azure Arc privilege-escalation critical network on-prem patch

← All CVEs