CVE-2026-26117Disclosure(microsoft / arc_enabled_servers_azure_connected_machine_agent)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft arc_enabled_servers_azure_connected_machine_agent systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • arc_enabled_servers_azure_connected_machine_agent

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • General: 5 classified signals
  • Peaked 3d ago at 7 mentions (2026-03-11); latest day: 1
  • 14 total mentions across 5 days

Affected systems

Vendors
Products
arc_enabled_servers_azure_connected_machine_agent

Deep dive

Activity timeline14 mentions / 5d
02457Mentions · 2026-03-10: 3Mentions · 2026-03-11: 7Mentions · 2026-03-12: 2Mentions · 2026-03-16: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-11: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-10: 3Technical Details · 2026-03-11: 4Technical Details · 2026-03-16: 1Technical Details · 2026-03-31: 103-1003-1103-1203-1603-31
Signal classification3 categories
Disclosure
857.1%
General
535.7%
Patch
17.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-103
Disclosure2General1
2026-03-117
Disclosure5General2
2026-03-122
General1Patch1
2026-03-161
Disclosure1
2026-03-311
General1
Full discourse14 posts
  • Steven Lim@0x534c
    Disclosure

    CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover CVE‑2026‑26117 is a high‑severity flaw in the Azure Arc Connected Machine agent for Windows that allows a low‑privileged local user to intercept internal agent communications, impersonate the machine’s Azure cloud identity, escalate privileges to NT AUTHORITY\SYSTEM, and even redirect the device to register with an attacker‑controlled Azure tenant. The below KQL help defender identify internet-facing Azure Arc Windows systems running vulnerable agent version that is subject LPE and potential cloud identity takeover. Cymulate Security Research on CVE-2026-26117 Link: https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/ KQL Code: https://github.com/SlimKQL/Detections.AI/blob/main/KQL/cve-2026-26117-hijacking-azure-arc-on-windows-for-local-privilege-escalation--cloud-identity-takeover.kql #Cybersecurity #AzureArc #LPE #DefenderXDR

    Post summary

    The text announces a new CVE-2026-26117 flaw in Azure Arc, explains its high‑severity impact, and provides detection KQL guidance, but it does not disclose an exploit or patch.

    19043314.0K
    6.1K followersView on X
  • Ilan Kalendarov@IKalendarov
    General

    Full write up https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/

    Post summary

    The excerpt merely points to a blog post about CVE‑2026‑26117, highlighting an Azure Arc Windows local privilege escalation leading to cloud identity takeover without disclosing PoC code, exploits, patches, or active use.

    011036162.2K
    716 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/

    Post summary

    The linked blog post announces CVE-2026-26117, detailing how attackers can hijack Azure Arc on Windows to achieve local privilege escalation and cloud identity takeover.

    1301082.0K
    153.0K followersView on X
  • Ilan Kalendarov@IKalendarov
    Disclosure

    We’ve disclosed CVE-2026-26117 affecting Azure Arc on Windows: a high severity local privilege escalation that can also be used to take over the machine’s cloud identity >>🧵

    Post summary

    The post announces a new high‑severity local privilege escalation flaw (CVE‑2026‑26117) in Azure Arc for Windows, describing its impact but providing no PoC, exploit code, or patch.

    33073610
    716 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/

    Post summary

    A blog post announces CVE‑2026‑26117, highlighting that attackers can hijack Azure Arc on Windows to achieve local privilege escalation and cloud identity takeover, but no PoC, exploit code, or mitigation is referenced in the snippet.

    01015800
    32.8K followersView on X
  • Kim Oppalfens (MVP) ✖️@TheWMIGuy
    Patch

    https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/ Verify your Arc agents are upto date.

    Post summary

    The text highlights a security advisory for CVE‑2026‑26117, recommending users update Azure Arc agents, but it provides no PoC, exploit, or technical depth.

    01010779
    4.6K followersView on X
  • VulnTracker@vuln_tracker
    General

    @0x534c CVE-2026-26117 in Azure Arc is exactly why hybrid cloud security is tricky. The KQL query makes this research immediately useful for threat hunters. Solid work! Track and monitor this CVE now: https://vulntracker.io/cves/CVE-2026-26117

    Post summary

    The tweet highlights a CVE in Azure Arc and references a KQL query that may aid threat hunters, but provides no deeper technical, exploit, or mitigation details.

    00020151
    397 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20127 2 - CVE-2026-30903 3 - CVE-2026-27944 4 - CVE-2026-28292 5 - CVE-2026-26117 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists five trending CVE identifiers with no additional information, claims, or technical details.

    00010163
    1.7K followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26117 | Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26117 https://t.co/B8s36e8GEz

    Post summary

    The excerpt references CVE-2026-26117, describing it as an elevation of privilege issue for Arc-enabled servers, but provides only minimal details and a link to an external resource.

    0000029
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26117 Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-26117

    Post summary

    The tweet announces CVE‑2026‑26117, describing an authentication bypass in Azure Windows Virtual Machine Agent that permits local privilege escalation, and links to its CVE record.

    00000179
    56.7K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover https://www.reddit.com/r/netsec/comments/1rqm1lr/cve202626117_hijacking_azure_arc_on_windows_for/

    Post summary

    The post discusses CVE‑2026‑26117, describing a local privilege escalation and cloud identity takeover vulnerability in Windows Azure Arc, with no evidence of exploits, patches, or active deployment.

    0000047
    300 followersView on X
  • Secwiser - Cyber Security Insights@Secwiserapp
    Disclosure

    Azure Arc Privilege Escalation via Cloud Identity CVE-2026-26117 describes a chain in Windows Azure Arc agent services (HIMDS, Guest Configuration, ARC Proxy) that allows a low-privileged user to hijack ARC service communications, impersonate the machine’s cloud identity, escalate to NT AUTHORITY\\SYSTEM, and redirect to attacker tenants. Read more: https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/ Discover the app: https://www.secwiser.com/app #AzureArc #CloudSecurity #PrivilegeEscalation #CVEs #Kubernetes #Azure #AWS #InfrastructureSecurity #CyberSecurity #DevOps #Secwiser

    Post summary

    The post highlights CVE‑2026‑26117, a privilege‑escalation flaw in Azure Arc agents that lets attackers hijack communications and elevate to SYSTEM, with additional technical details linked in the Cymulate blog.

    0000035
    17 followersView on X
  • VulnTracker@vuln_tracker
    General

    @Dinosn CVE-2026-26117 hits different when you realize Azure Arc bridges everything. This vulnerability deserves all the attention it's getting. https://vulntracker.io/cves/CVE-2026-26117

    Post summary

    The tweet merely references the CVE and notes it deserves attention, but provides no technical or actionable information.

    0000069
    397 followersView on X
  • Ben Zamir@BenZamir_X
    Disclosure

    During our hybrid environment research at Cymulate, I discovered CVE-2026-26117 in Azure Arc. A compromised Arc machine can allow a low-privileged user to escalate locally and abuse the Arc identity flow, potentially pivoting into Azure. https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/

    Post summary

    Cymulate announces the discovery of CVE‑2026‑26117 in Azure Arc, detailing that a low‑privileged user can elevate locally and exploit the Arc identity flow to pivot into Azure resources.

    0000039
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftarc_enabled_servers_azure_connected_machine_agent---

Explore more