Description
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
Published: 2026-08-20
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow or wraparound flaw in Azure Data Manager for Energy permits an attacker who has authorized access to execute code over the network. The vulnerability arises when the system mismanages arithmetic operations and is classified as CWE-190.

Affected Systems

Microsoft Azure Data Manager for Energy is the affected product. No specific versions are listed, so all deployments of this product may be susceptible.

Risk and Exploitability

The flaw has a CVSS base score of 8.5, indicating high severity. EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, so known exploitation activity is unknown. The typical attack path requires valid credentials and network connectivity to the service, making it a network‑based exploitation for an authorized user.

Generated by OpenCVE AI on August 21, 2026 at 01:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update for Azure Data Manager for Energy as soon as it is released.
  • Restrict inbound traffic to the service by permitting only trusted IP ranges or subnets.
  • Enforce role‑based access controls to limit who can invoke the affected API endpoints.
  • Monitor audit logs for unusual RPC or API calls that could indicate exploitation.

Generated by OpenCVE AI on August 21, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_data_manager_for_energy:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
Title Azure Data Manager for Energy Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft azure Data Manager For Energy
Weaknesses CWE-190
CPEs cpe:2.3:a:microsoft:azure_data_manager_for_energy:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Data Manager For Energy
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Data Manager For Energy
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:36.435Z

Reserved: 2026-08-03T20:57:58.964Z

Link: CVE-2026-69419

cve-icon Vulnrichment

Updated: 2026-08-21T15:46:50.149Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:59.980

Modified: 2026-09-04T19:08:37.583

Link: CVE-2026-69419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:45:07Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound