VYPR

Azure Arc

by Microsoft

CVEs (11)

  • CVE-2026-69399CriSep 17, 2026
    risk 0.65cvss 10.0epss 0.00

    Azure Arc Elevation of Privilege Vulnerability

  • CVE-2026-69555CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-65816CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70009CriSep 17, 2026
    risk 0.61cvss 9.3epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62895HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-24302HigFeb 5, 2026
    risk 0.56cvss 8.6epss 0.02

    Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55316HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2022-38007HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability

  • CVE-2025-26627HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2019-0804MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'.