Azure Arc
by Microsoft
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24302 | Hig | 0.56 | 8.6 | 0.02 | Feb 5, 2026 | Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-26141 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55316 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. | ||
| CVE-2022-38007 | Hig | 0.51 | 7.8 | 0.01 | Sep 13, 2022 | Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | ||
| CVE-2025-26627 | Hig | 0.46 | 7.0 | 0.01 | Mar 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | ||
| CVE-2019-0804 | Med | 0.43 | 6.5 | 0.05 | Apr 9, 2019 | An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'. |
- risk 0.56cvss 8.6epss 0.02
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- risk 0.51cvss 7.8epss 0.00
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists in the way Azure WaLinuxAgent creates swap files on resource disks, aka 'Azure Linux Agent Information Disclosure Vulnerability'.