Description
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of special elements used in a command, which Microsoft classifies as a command injection flaw (CWE‑77). An attacker who has authorized access to the Azure Monitor Agent Linux Extension can construct input that is passed unchanged to the underlying operating‑system shell, enabling the execution of arbitrary commands. The primary consequence is elevation of privileges over the network, allowing the attacker to gain higher authority on the host or potentially on other systems accessed by the agent.

Affected Systems

The flaw affects Microsoft’s Azure Monitor Agent Linux Extension. No specific version applicability was disclosed, so all operational instances of this agent are potentially vulnerable until the Microsoft update is applied.

Risk and Exploitability

The CVSS score of 7.2 indicates a high‑severity condition. The EPSS score of less than 1 % suggests that exploitation is unlikely at present, and the vulnerability has not been reported as part of the CISA KEV catalog. The attack requires an attacker to possess legitimate credentials or some authorized capability to interact with the agent; from that position the actor can craft malicious input and cause the agent to run commands with elevated privileges. Consequently, internal adversaries with valid access or compromised credentials pose the highest risk.

Generated by OpenCVE AI on August 12, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Microsoft’s latest security update for Azure Monitor Agent Linux Extension to fix the command injection flaw.
  • Restrict the agent’s network connectivity to known, trusted IP addresses or apply firewall rules that limit access to the service.
  • Run the agent with the minimum privileges required for its operation, ensuring it does not have escalated or root permissions.
  • Review and enforce strict user permissions for anyone allowed to manage or configure the agent, reducing the chance that an authorized user can misuse the flaw.

Generated by OpenCVE AI on August 12, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Title Azure Monitor Agent Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Monitor Agent Linux Extension
Weaknesses CWE-77
CPEs cpe:2.3:a:microsoft:azure_monitor_agent_linux_extension:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Monitor Agent Linux Extension
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Monitor Agent Linux Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-12T17:54:05.782Z

Reserved: 2026-05-18T23:53:33.897Z

Link: CVE-2026-47299

cve-icon Vulnrichment

Updated: 2026-08-12T14:01:35.623Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T17:17:59.100

Modified: 2026-08-12T15:17:34.223

Link: CVE-2026-47299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T17:30:06Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')