• PATCH AVAILABLE

CVE-2026-62834: pre-auth privilege escalation in Microsoft Azure Data Factory

An unauthenticated remote attacker can elevate privileges in Microsoft Azure Data Factory by exploiting improper verification of a cryptographic signature (CVE-2026-62834). Microsoft identifies Azure Data Factory as affected; no fixed version numbers are listed in the advisory. The flaw is exploitable over the network without credentials or user interaction, and it carries a critical CVSS 3.1 score of 9.8.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00529
CWE
CWE-347
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this vulnerability requires no credentials or user interaction, so exposed Azure Data Factory endpoints should be treated as high risk and remediated promptly.

What is CVE-2026-62834?

An unauthenticated remote attacker can elevate privileges in Microsoft Azure Data Factory by exploiting improper verification of a cryptographic signature (CVE-2026-62834). Microsoft identifies Azure Data Factory as affected; no fixed version numbers are listed in the advisory. The flaw is exploitable over the network without credentials or user interaction, and it carries a critical CVSS 3.1 score of 9.8. The weakness is classified as CWE-347 (Improper Verification of Cryptographic Signature).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Azure Data Factory are affected?

BRANCHAFFECTEDFIXED
Azure Data Factory-

Is CVE-2026-62834 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-62834

  1. Apply Microsoft’s updates or guidance for Azure Data Factory as soon as vendor patches are published.
  2. Restrict network exposure: block or limit access to Azure Data Factory management endpoints from untrusted networks.
  3. Monitor logs and audit trails for unexpected privilege changes or anomalous activity related to Data Factory accounts and pipelines.
  4. Follow Microsoft’s mitigation guidance and watch the vendor advisory for confirmed fixed versions and deployment instructions.

Frequently asked questions

Is CVE-2026-62834 being actively exploited?

There are no public reports of exploitation of CVE-2026-62834 as of 2026-09-29.

Which Azure Data Factory versions are affected by CVE-2026-62834?

Microsoft lists Azure Data Factory as affected; the advisory does not publish specific fixed version numbers in the provided facts.

Is there a patch for CVE-2026-62834?

A patch is indicated as available in the advisory facts, but no fixed version identifiers are listed; apply Microsoft’s updates or guidance when the vendor provides them.

Does CVE-2026-62834 require authentication?

No. The vulnerability can be exploited without authentication or user interaction against Azure Data Factory, allowing remote privilege elevation.

References