CVE-2026-69435: Azure SRE Agent Elevation of Privilege Vulnerability
Published Oct 8, 2026
·Updated
Azure SRE Agent Elevation of Privilege Vulnerability
Other sources
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure SRE Agent
Microsoft Azure SRE Agent
Event History
Oct 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already be authorized and able to reach the Azure SRE Agent over the network. No user interaction is required.
2
What is the likely impact of successful exploitation?
A successful attacker can elevate privileges. The available scoring information indicates high confidentiality and integrity impact, with no availability impact indicated.