Description
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-20
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery flaw in Azure Virtual Machines that can be exploited by an authorized attacker to gain elevated privileges on the network. The weakness is classified as CWE‑918, indicating that improper validation of user‑supplied URLs allows the attacker to manipulate outbound requests. If successfully exploited, the attacker can bypass normal access controls and execute privileged operations within the virtual machine environment.

Affected Systems

Microsoft Azure Virtual Machines

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. The likely attack vector is an SSRF that requires authorized access to the virtual machine; the attacker must have some level of authenticated control to craft the malicious request.

Generated by OpenCVE AI on August 21, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Azure Virtual Machines security update that addresses the SSRF flaw
  • Configure outbound network restrictions to limit which endpoints the VM can contact, mitigating SSRF exploitation
  • Review and tighten virtual machine access controls to ensure only trusted users have privilege to configure network settings
  • Enable and regularly review audit logs for anomalous outbound requests from virtual machines

Generated by OpenCVE AI on August 21, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_virtual_machines:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft azure Virtual Machine
Vendors & Products Microsoft azure Virtual Machine

Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
Title Azure Virtual Machines Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Virtual Machines
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:azure_virtual_machines:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Virtual Machines
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Virtual Machine Azure Virtual Machines
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:38.914Z

Reserved: 2026-08-03T21:12:04.477Z

Link: CVE-2026-69543

cve-icon Vulnrichment

Updated: 2026-08-21T15:32:06.968Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:18:00.270

Modified: 2026-08-26T15:08:57.987

Link: CVE-2026-69543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T00:45:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)