HarborGuard / CVE
Back to search
HIGHCVE-2026-26141Published Modified CNA microsoft

CVE-2026-26141: Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
1.3.74
Affected Products
1
Affected packages
  • Microsoft / Azure Automation Hybrid Worker Windows Extension
    < 1.3.74 (from 1.0.0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C