CVE-2026-24304: Azure Cosmos DB Remote Code Execution Vulnerability
Azure Cosmos DB Remote Code Execution Vulnerability
Other sources
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
— Microsoft
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24304?
CVE-2026-24304 is classified as a critical vulnerability due to its potential for elevation of privilege.
How do I fix CVE-2026-24304?
To mitigate CVE-2026-24304, ensure that you apply the latest security updates from Microsoft for Azure Resource Manager.
Who is affected by CVE-2026-24304?
CVE-2026-24304 affects users of Microsoft Azure Resource Manager who have improper access controls configured.
What are the risks associated with CVE-2026-24304?
The primary risk of CVE-2026-24304 is that an unauthorized user could elevate their privileges, leading to potential unauthorized access and data compromise.
Is there a workaround for CVE-2026-24304?
There are no known workarounds for CVE-2026-24304; the recommended action is to apply the available updates.