critical · CVSS v3 9.3
CVE-2026-70009
CVE‑2026‑70009 is a path‑traversal flaw in Azure Arc that lets an unauthenticated attacker gain elevated privileges over the network. The vu
Overview
CVE‑2026‑70009 is a path‑traversal flaw in Azure Arc that lets an unauthenticated attacker gain elevated privileges over the network. The vulnerability can be exploited to read or modify restricted files and execute arbitrary code on Azure‑Arc‑enabled hosts. It is rated critical with a CVSS v3 score of 9.3.
Description
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Impact
The flaw compromises confidentiality, integrity, and availability of the affected hosts. An attacker can read or tamper with system files, execute code with elevated privileges, and potentially disrupt services or exfiltrate data. Azure Arc users running on-premises or hybrid workloads are directly impacted, as the vulnerability is exploitable over the network without local authentication.
Remediation
1. Apply the latest Microsoft patch or upgrade to the newest Azure Arc agent version. 2. Restrict network access to the Arc agent by using firewall rules or Azure Network Security Groups. 3. Enforce least‑privilege for Arc service principals and disable unused features. 4. Enable Azure Policy or Azure Security Center to monitor for abnormal file access or privilege escalation. 5. Conduct regular vulnerability scans and verify that the path‑traversal fix is in place.
Risk context
With a CVSS v3 score of 9.3 and no EPSS data, the vulnerability is considered highly urgent. Immediate patching and network hardening are recommended to mitigate the risk of privilege escalation and potential data compromise.
Affected products
- Azure Arc
- Azure Arc‑enabled servers
- Azure Arc‑enabled Kubernetes
- Azure Arc‑enabled data services
- Azure Arc‑enabled SQL
- Azure Arc‑enabled VMware
- Azure Arc‑enabled GitHub
- Azure Arc‑enabled Azure services
Scores
- Severity
- critical
- CVSS v2
- 8.5
- CVSS v3
- 9.3
- CVSS v4
- —
- EPSS
- —