HarborGuard / CVE
Back to search
HIGHCVE-2026-40381Published Modified CNA microsoft

CVE-2026-40381: Azure Connected Machine Agent Elevation of Privilege Vulnerability

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
1.63
Affected Products
1
Affected packages
  • Microsoft / Azure Connected Machine Agent
    < 1.63 (from 1.0.0)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C