CVE-2026-26145Disclosure(microsoft / azure_synapse)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_synapse systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_synapse

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-03)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
azure_synapse

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-02: 1Mentions · 2026-07-03: 2Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 207-0207-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-032
Disclosure1Patch1
Full discourse3 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 7. 2 Microsoft Azure Synapse の特権昇格の脆弱性 CVE-2026-26145 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26145

    Post summary

    The post announces the existence of a privilege‑escalation vulnerability (CVE‑2026‑26145) affecting Microsoft Azure Synapse, providing a link to the vendor advisory but no additional details.

    10100129
    91 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 CVE-2026-26145 「…された脆弱性を解決するために、お客様が取るべきアクションはありません」 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 4.8 / 4.3 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2072841492713083236

    Post summary

    Microsoft issued a security update for CVE‑2026‑26145, a privilege‑escalation flaw rated emergency, and users are instructed that no action is needed because the fix is already applied.

    1000057
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26145 Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26145

    Post summary

    A brief disclosure of CVE-2026-26145, indicating improper access control in Azure Synapse that could allow an authorized attacker to elevate privileges across a network.

    00000663
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_synapse---

Explore more