• PATCH AVAILABLE

CVE-2026-70009: path traversal in Microsoft Azure ARC

Remote attackers can use a path traversal flaw to elevate privileges against Azure ARC. CVE-2026-70009 is a path traversal vulnerability (CWE-22) that allows an unauthenticated network attacker to access or overwrite restricted files and gain elevated control of the affected Azure ARC installation; it requires network access and no user interaction. Microsoft identifies Azure ARC as affected, but vendor fixed-version details are not listed in the supplied facts.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00534
CWE
CWE-22
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw requires no authentication and has a critical CVSS 9.8 rating, so immediately limit network exposure and prioritize vendor remediation guidance.

What is CVE-2026-70009?

Remote attackers can use a path traversal flaw to elevate privileges against Azure ARC. CVE-2026-70009 is a path traversal vulnerability (CWE-22) that allows an unauthenticated network attacker to access or overwrite restricted files and gain elevated control of the affected Azure ARC installation; it requires network access and no user interaction. Microsoft identifies Azure ARC as affected, but vendor fixed-version details are not listed in the supplied facts. The weakness is classified as CWE-22 (Path Traversal).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Azure ARC are affected?

BRANCHAFFECTEDFIXED
Azure ARC-

Is CVE-2026-70009 being exploited?

There are no public reports of exploitation as of 2026-09-29; CISA has not added this issue to the Known Exploited Vulnerabilities catalog and no public exploit code is available.

How to fix CVE-2026-70009

  1. Apply Microsoft’s updates or guidance for Azure ARC as soon as vendor patches are confirmed available.
  2. Restrict network exposure of Azure ARC endpoints to trusted management networks and block unneeded inbound access.
  3. Monitor Azure ARC logs and file integrity for unexpected file access or modifications that may indicate path traversal activity.
  4. Implement additional compensating controls such as host-based file protections and least-privilege service accounts.

Frequently asked questions

Is CVE-2026-70009 being actively exploited?

There are no public reports of exploitation as of 2026-09-29; CISA has not listed it in the Known Exploited Vulnerabilities catalog and no public exploit code is available.

Which Azure ARC versions are affected by CVE-2026-70009?

The supplied information identifies Azure ARC as affected but does not list specific version numbers or fixed releases.

Is there a patch for CVE-2026-70009?

Vendor guidance indicates a patch is available; the supplied facts do not include the fixed-version identifiers, so follow Microsoft’s official update instructions for Azure ARC.

Does CVE-2026-70009 require authentication?

No; the vulnerability allows unauthenticated network attackers to exploit a path traversal condition against Azure ARC without user interaction.

References