CVE-2026-81349: Azure HDInsight Ambari Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.2)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.

FAQ

What privileges an attacker could gain with a successful exploitation? An attacker with the Service Operator role in Azure HDInsight Ambari can exploit a command injection flaw in the HDFS REBALANCEHDFS custom command to execute arbitrary system commands as the hdfs user on the NameNode. What action should customers take to address this vulnerability? Customers should recreate affected Azure HDInsight clusters so they are provisioned with the updated image. The fix is included in the June 29, 2026 Azure HDInsight release, image 2606012120, and later images. For instructions, see Set up clusters in HDInsight with Hadoop, Spark, and Kafka.

Affected Products (1)

Azure

  • Azure HDInsight

Security Updates (1)

Acknowledgments

Jianyang Song

Revision History

  • 2026-09-08: Information published.