CVE-2026-26141Disclosure(microsoft / azure_automation_hybrid_worker_windows_extension)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_automation_hybrid_worker_windows_extension

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
azure_automation_hybrid_worker_windows_extension

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-16: 1Mentions · 2026-03-31: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 103-1003-1603-31
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-161
Disclosure1
2026-03-311
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26141 Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-26141

    Post summary

    The text announces CVE-2026-26141, a local privilege escalation vulnerability in Azure Arc due to improper authentication, with no evidence of PoC, exploit code, or active exploitation.

    00010181
    56.7K followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26141 | Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26141 https://t.co/wcdIJmXv3X

    Post summary

    The excerpt simply announces the existence of CVE‑2026‑26141 and links to a blog post, without providing concrete technical, exploit, or mitigation information.

    0000028
    1 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Microsoft discloses three Azure VM elevation of privilege flaws (CVE-2026-26141, -26117, -23665) allowing authorized users to gain local admin on Arc-enabled Windows and Linux VMs. #CloudSecurity https://threatcluster.io/cluster/multiple-elevation-of-privilege-vulnerabilities-in-azure-arc-2ff22026

    Post summary

    Microsoft has announced three Azure VM privilege‑escalation vulnerabilities, yet no PoC, exploit, active usage, patch, or false‑positive discussion is present.

    0000038
    100 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_automation_hybrid_worker_windows_extension---

Explore more