Description
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 7.2 High
EPSS: 1.0% Low
KEV: No
Impact: Elevation of Privilege
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a classic OS command injection flaw located in Azure HDInsight’s Ambari component. An attacker who already has authorized access within the HDInsight environment can inject and execute arbitrary operating‑system commands, granting them elevated administrative privileges over the network. The flaw is a misuse of untrusted input in command construction, as classified by CWE‑78.

Affected Systems

Microsoft Azure HDInsight is the affected product. No specific version numbers are listed in the available information, so any deployment of Azure HDInsight may be impacted until the patch is applied.

Risk and Exploitability

The CVSS score of 7.2 places this issue in the high severity range, and although the EPSS score is not available, the lack of an entry in the CISA KEV catalog suggests that widespread exploitation has not yet been observed. The likely attack vector requires an authenticated user to interact with the Ambari service over the network; no remote anonymous exploitation is described. Given the high score and potential for privilege escalation, the risk to an organization using Azure HDInsight is significant if no mitigation is performed.

Generated by OpenCVE AI on September 9, 2026 at 04:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official security update for Azure HDInsight from the Microsoft update guide (CVE-2026-81349).
  • Restrict user permissions for Ambari and ensure that only trusted administrators have access to command execution endpoints.
  • Audit and monitor Ambari service logs for suspicious command execution activity to detect potential misuse.

Generated by OpenCVE AI on September 9, 2026 at 04:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft azure Hdinsight
CPEs cpe:2.3:a:microsoft:azure_hdinsight:*:*:*:*:*:*:*:*
Vendors & Products Microsoft azure Hdinsight

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Title Azure HDInsight Ambari Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Hdinsights
Weaknesses CWE-78
CPEs cpe:2.3:a:microsoft:azure_hdinsights:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Hdinsights
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


Subscriptions

Microsoft Azure Hdinsight Azure Hdinsights
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:49.641Z

Reserved: 2026-08-26T18:40:19.855Z

Link: CVE-2026-81349

cve-icon Vulnrichment

Updated: 2026-09-09T09:59:58.779Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:52.810

Modified: 2026-09-23T19:55:14.127

Link: CVE-2026-81349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:00:08Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')