CVE-2026-70340: Azure CycleCloud Elevation of Privilege Vulnerability
Published Aug 11, 2026
·Updated
Azure CycleCloud Elevation of Privilege Vulnerability
Other sources
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft Azure Cyclecloud
Microsoft Azure CycleCloud 8.9.1<8.9.1
8.9.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.9.1
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverity
Data Sourced
via NVD·05:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-70340?
CVE-2026-70340 has a high severity rating of 8.1.
2
What can an attacker do with CVE-2026-70340?
An attacker can elevate privileges over a network due to the lack of authorization in Azure CycleCloud.
3
How do I fix CVE-2026-70340?
To fix CVE-2026-70340, apply the latest security updates for Microsoft Azure CycleCloud.
4
What software is affected by CVE-2026-70340?
CVE-2026-70340 affects Microsoft Azure CycleCloud, particularly version 8.9.1.
5
When was CVE-2026-70340 published?
CVE-2026-70340 was published on August 11, 2026.