VYPR

Azure Arc

by Microsoft

CVEs (6)

  • CVE-2026-24302HigFeb 5, 2026
    risk 0.56cvss 8.6epss 0.02

    Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2025-55316HigSep 9, 2025
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2022-38007HigSep 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability

  • CVE-2025-26627HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2019-0804MedApr 9, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'.