CVE-2026-26117 is an authentication bypass vulnerability in the Microsoft Arc Enabled Servers Azure Connected Machine Agent that allows a local, low-privileged attacker to achieve privilege escalation. Rated 7.8 High, this flaw has a local attack vector and low attack complexity, enabling an attacker to gain high impact on confidentiality, integrity, and availability without user interaction. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.61CPE matchmatch criteria | cpe:2.3:a:microsoft:arc_enabled_servers_azure_connected_machine_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.