CVE-2026-47299: Azure Monitor Agent Elevation of Privilege Vulnerability
Published Aug 11, 2026
·Updated
Azure Monitor Agent Elevation of Privilege Vulnerability
Other sources
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Azure Monitor Agent
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-47299?
CVE-2026-47299 has a severity rating of high at 7.2.
2
What type of vulnerability is CVE-2026-47299?
CVE-2026-47299 is a command injection vulnerability allowing elevation of privilege.
3
Who is affected by CVE-2026-47299?
CVE-2026-47299 affects users of Microsoft Azure Monitor Agent.
4
How do I fix CVE-2026-47299?
To mitigate CVE-2026-47299, update Microsoft Azure Monitor Agent to the latest patched version.
5
What can attackers accomplish using CVE-2026-47299?
An attacker can exploit CVE-2026-47299 to elevate their privileges on the network.