CVE-2026-83948: Microsoft Azure CLI Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.
Other sources
Microsoft Azure CLI Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.2.1
Event History
Frequently Asked Questions
What level of access and interaction does exploitation require?
An attacker must be authorized and have low privileges. Exploitation also requires user interaction and has high attack complexity.
What could a successful exploit allow?
Successful exploitation could allow code execution and affect confidentiality, integrity, and availability at high impact. The scope is changed, meaning the impact can extend beyond the initially vulnerable security authority.
Can this be exploited remotely?
Yes. The attack vector is network-based, so exploitation can be performed over a network rather than requiring local access.