Improper Authentication in Microsoft Azure Local Disconnected Operations
CVE-2026-42822

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
18 May 2026

What is CVE-2026-42822?

The vulnerability in Azure Local Disconnected Operations arises from improper authentication, enabling unauthorized attackers to gain elevated privileges across a network. This weakness can potentially lead to unauthorized access to sensitive systems, compromising the integrity and confidentiality of data. It is crucial for organizations using Microsoft Azure to understand this risk and implement protective measures as advised in the vendor's guidance.

Affected Version(s)

Azure Local 1.0.0 < 2604.2.25645

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.