CVE-2026-26148 is a local privilege escalation vulnerability affecting the Microsoft Azure AD SSH Login Extension for Linux, allowing an unauthorized attacker to elevate privileges by manipulating externally initialized trusted variables or data stores. Rated 8.1 High severity (CVSS:3.1/AV:L/AC:H), successful exploitation, though complex, grants high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, no public exploit code available, and the EPSS score indicates a very low probability of exploitation, despite minimal community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.033370002CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_ad_ssh_login_extension_for_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.