Description
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-20
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose sensitive information across the network. The vendor identified this flaw as CWE‑204, a weakness that enables unintended information disclosure. As a result, confidential data that should be protected by the system could be exposed to an attacker, potentially leading to compromised customer data and breach of compliance requirements.

Affected Systems

Microsoft Azure Stack HCI devices are affected by this vulnerability. No specific version information was provided, so all current and future deployments of Azure Stack HCI should be considered at risk until a patch is distributed.

Risk and Exploitability

The CVSS score of 8.6 classifies this flaw as high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, network‑based access to the HCI cluster; authentication is not required. Once an attacker can reach the vulnerable interface, they can leverage the response difference to retrieve information that should remain confidential.

Generated by OpenCVE AI on August 21, 2026 at 00:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or software update released by Microsoft for Azure Stack HCI
  • Restrict network access to management interfaces by limiting inbound traffic to trusted management networks and closing unused ports
  • Monitor system and network logs for unusual response patterns or repeated access attempts and investigate promptly

Generated by OpenCVE AI on August 21, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_stack_hci:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
Title Azure Stack HCI Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft azure Stack Hci
Weaknesses CWE-204
CPEs cpe:2.3:a:microsoft:azure_stack_hci:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Stack Hci
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Azure Stack Hci
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:34:36.502Z

Reserved: 2026-08-03T21:09:40.781Z

Link: CVE-2026-69519

cve-icon Vulnrichment

Updated: 2026-08-21T15:34:14.106Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:18:00.123

Modified: 2026-08-25T16:08:36.103

Link: CVE-2026-69519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T02:00:04Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy