CVE-2026-26141: Hybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2026-Mar
- Released
- 2026-03-10
- EPSS Score
- 0.04% (percentile: 12.1%)
Description
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain ELEVATED privileges.
Affected Products (1)
Azure
- Azure Automation Hybrid Worker Windows Extension
Security Updates (1)
Acknowledgments
Michal Kamensky with Microsoft
Revision History
- 2026-03-10: Information published.