CVE-2026-24304Disclosure(microsoft / azure_resource_manager)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_resource_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_resource_manager

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-01-28); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
azure_resource_manager

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-03-27: 1Mentions · 2026-05-21: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 1Technical Details · 2026-05-21: 101-2801-3003-2705-21
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-01-301
Disclosure1
2026-03-271
Disclosure1
2026-05-211
Disclosure1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-24304 - Critical privilege escalation in #Azure Resource Manager. Improper access control allows authorized users to elevate privileges over network. CVSS 9.9. No patch available yet. #CVE #Microsoft #cybersecurity #inforec #infosecurity More https://www.valtersit.com/cve/CVE-2026-24304/

    Post summary

    The post announces CVE‑2026‑24304, a critical privilege‑escalation flaw in Azure Resource Manager with a CVSS score of 9.9, noting that no patch is yet available and providing no PoC or exploitation details.

    0001098
    904 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-24304 (CVSS:9.9, CRITICAL) is Awaiting Analysis. Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network...https://nvd.nist.gov/vuln/detail/CVE-2026-24304 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-24304 with a high CVSS score and a brief privilege‑escalation description, but offers no PoC, exploit code, evidence of active attacks, or patch information.

    0000142
    171 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2026-24306 ❗ CVE-2026-24304 ❗ CVE-2026-21264 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-8/ https://t.co/JOPrIfOtg2

    Post summary

    The tweet announces three Microsoft CVEs and provides links for more information, indicating a vulnerability disclosure announcement.

    00000130
    6.6K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-24304 | Azure Resource Manager Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-24304 https://t.co/mV5sqyKp4u

    Post summary

    The post references CVE‑2026‑24304 as an Azure Resource Manager elevation‑of‑privilege vulnerability via a blog link, with no evidence of PoC, exploit, active use, or mitigation.

    0000046
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_resource_manager---

Explore more