CVE-2026-65816: Azure Arc Elevation of Privilege Vulnerability
Published Aug 20, 2026
·Updated
Azure Arc Elevation of Privilege Vulnerability
Other sources
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Azure Web Apps
Event History
Aug 20, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates no privileges are required and no user interaction is needed.
2
What level of access does an attacker need to attempt exploitation?
The vulnerability is network-accessible and has low attack complexity according to the CVSS vector.
3
What could happen after successful exploitation?
The CVSS vector rates confidentiality, integrity, and availability impact as high, with scope changed.