• PATCH AVAILABLE

CVE-2026-69555: pre-auth privilege escalation in Microsoft Azure ARC

An unauthenticated network attacker can elevate privileges in Microsoft Azure ARC, allowing full impact on confidentiality and integrity (CVE-2026-69555). The vulnerability is an incorrect authorization (CWE-863) in Azure ARC; affected versions are listed as Azure ARC in vendor data, but no specific fixed releases are provided in the supplied facts. An attacker only needs network access — no valid credentials or user interaction are required — to exploit the flaw according to the published analysis.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00798
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, pre-auth vulnerability (no login needed) that yields full compromise potential, so immediately reduce network exposure and follow Microsoft guidance.

What is CVE-2026-69555?

An unauthenticated network attacker can elevate privileges in Microsoft Azure ARC, allowing full impact on confidentiality and integrity (CVE-2026-69555). The vulnerability is an incorrect authorization (CWE-863) in Azure ARC; affected versions are listed as Azure ARC in vendor data, but no specific fixed releases are provided in the supplied facts. An attacker only needs network access — no valid credentials or user interaction are required — to exploit the flaw according to the published analysis.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Azure ARC are affected?

BRANCHAFFECTEDFIXED
Azure ARC-

Is CVE-2026-69555 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-69555

  1. Apply vendor updates immediately if Microsoft publishes fixed releases or vendor guidance.
  2. Restrict network exposure of Azure ARC endpoints to trusted management networks and VPNs.
  3. Monitor Azure ARC logs and related identity and access logs for unexpected privilege changes or anomalous activity.
  4. Follow Microsoft security advisories and implement recommended mitigations until fixed versions are available.

Frequently asked questions

Is CVE-2026-69555 being actively exploited?

There are no public reports of exploitation of CVE-2026-69555 as of 2026-09-29.

Which Azure ARC versions are affected by CVE-2026-69555?

The facts list the affected branch as Azure ARC but do not specify particular version numbers or builds that are affected.

Is there a patch for CVE-2026-69555?

Patch availability is indicated as true in the supplied data, but no fixed version numbers are provided; follow Microsoft advisories for published fixes and installation instructions.

Does CVE-2026-69555 require authentication?

No; the vulnerability in Azure ARC does not require authentication — an attacker only needs network access to attempt exploitation.

References