Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
What privileges an attacker could gain with a successful exploitation? An attacker with the Service Operator role in Azure HDInsight Ambari can exploit a command injection flaw in the HDFS REBALANCEHDFS custom command to execute arbitrary system commands as the hdfs user on the NameNode. What action should customers take to address this vulnerability? Customers should recreate affected Azure HDInsight clusters so they are provisioned with the updated image. The fix is included in the June 29, 2026 Azure HDInsight release, image 2606012120, and later images. For instructions, see Set up clusters in HDInsight with Hadoop, Spark, and Kafka.
Jianyang Song