Description
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-20
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from the use of incorrectly‑resolved names or references within Azure Arc, permitting an attacker who is not authorized to elevate privileges over a network. This flaw is classified as an access‑control weakness (CWE‑706). If exploited, an attacker could gain higher-level permissions on Azure services, potentially accessing sensitive data or executing privileged operations.

Affected Systems

The affected product is Microsoft Azure Web Apps with Azure Arc integration. No specific product or version qualifiers are listed in the CNA data.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity, but the EPSS value is unavailable. The vulnerability is not marked in the CISA KEV list. Attacks would likely use remote network access to reach the Azure Arc components; however, no explicit prerequisites are detailed in the advisory, so further information from Microsoft is needed to determine exact attack steps. The lack of a publicly listed exploit means the risk of exploitation remains uncertain, but the severity warrants immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure Web Apps update that addresses the Azure Arc privilege‑escalation flaw, as directed by the Microsoft security update guide.
  • If the update is not yet available, disable Azure Arc integration on the affected Web Apps to eliminate the attack surface.
  • Restrict network access to Azure Arc endpoints using network security groups or firewall rules to limit potential attackers.

Generated by OpenCVE AI on August 21, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_web_apps:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Title Azure Arc Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Web Apps
Weaknesses CWE-706
CPEs cpe:2.3:a:microsoft:azure_web_apps:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Web Apps
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Web Apps
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:34.320Z

Reserved: 2026-07-22T21:36:47.630Z

Link: CVE-2026-65816

cve-icon Vulnrichment

Updated: 2026-08-21T20:06:29.030Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:55.597

Modified: 2026-08-24T18:05:57.350

Link: CVE-2026-65816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T00:45:06Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference