Description
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the Azure SRE Agent allows an attacker who already has authorized network access to elevate their privileges on the host. This flaw, identified as CWE-862, can lead to remote privilege escalation and potentially permit execution of arbitrary code or operations beyond the attacker’s intended scope.

Affected Systems

Microsoft Azure SRE Agent is affected. No specific version information is provided, so all deployments of the agent that do not include the fix are potentially vulnerable.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified; however, the flaw requires that the attacker already have some level of network or authorized access. The missing authorization check implies that the attack vector is likely remote over a network connection to the agent. Because no workaround is known, the risk remains high until a patch is applied.

Generated by OpenCVE AI on August 7, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and deploy the Microsoft patch or update for Azure SRE Agent as soon as it is released from the MSRC advisory.
  • Configure firewall rules to restrict network traffic to the SRE Agent, allowing connections only from trusted management hosts or IP ranges.
  • Enforce least privilege on accounts that interact with the agent, disable unnecessary permissions, and enable audit logging to detect attempts to elevate privileges.

Generated by OpenCVE AI on August 7, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Title Azure SRE Agent Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Sre Agent
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:azure_sre_agent:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Sre Agent
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Sre Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-06T23:22:10.193Z

Reserved: 2026-07-14T21:10:38.082Z

Link: CVE-2026-62830

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:04Z

Weaknesses