CVE-2026-70009: Azure Arc Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Azure Arc Elevation of Privilege Vulnerability
Other sources
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure ARC
Microsoft Azure ARC
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require credentials or user interaction?
No. The vulnerability is rated with no privileges required and no user interaction required, with network attack vector and low attack complexity.
2
What is the expected security impact if exploited?
The provided metrics indicate high impact to integrity and low impact to confidentiality. They indicate no direct availability impact and a changed scope.