CVE-2026-47299: Azure Monitor Agent Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.2)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.

FAQ

What kind of security feature could be bypassed by successfully exploiting this vulnerability? Successfully exploiting this vulnerability could bypass extension allowlist–based protections that are intended to limit which Azure Arc or Azure VM extensions can perform actions on a machine. In certain hardened configurations, this could allow a monitoring-only extension to run commands with elevated privileges in ways that were not intended by the security configuration.

Affected Products (1)

Azure

  • Azure Monitor Agent Linux Extension

Security Updates (1)

Acknowledgments

<a href="https://twitter.com/ronmasas">Ron Masas</a>

Revision History

  • 2026-08-11: Information published.