
CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover CVE‑2026‑26117 is a high‑severity flaw in the Azure Arc Connected Machine agent for Windows that allows a low‑privileged local user to intercept internal agent communications, impersonate the machine’s Azure cloud identity, escalate privileges to NT AUTHORITY\SYSTEM, and even redirect the device to register with an attacker‑controlled Azure tenant. The below KQL help defender identify internet-facing Azure Arc Windows systems running vulnerable agent version that is subject LPE and potential cloud identity takeover. Cymulate Security Research on CVE-2026-26117 Link: https://cymulate.com/blog/cve-2026-26117-azure-arc-windows-lpe-cloud-identity-takeover/ KQL Code: https://github.com/SlimKQL/Detections.AI/blob/main/KQL/cve-2026-26117-hijacking-azure-arc-on-windows-for-local-privilege-escalation--cloud-identity-takeover.kql #Cybersecurity #AzureArc #LPE #DefenderXDR
Post summary
The text announces a new CVE-2026-26117 flaw in Azure Arc, explains its high‑severity impact, and provides detection KQL guidance, but it does not disclose an exploit or patch.











