Elevation of Privilege in Azure CycleCloud by Microsoft
CVE-2026-58279

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 July 2026

What is CVE-2026-58279?

A missing authorization flaw in Azure CycleCloud permits an authorized attacker to escalate privileges, potentially compromising network integrity and user data security. This vulnerability highlights the need for robust access controls to safeguard against unauthorized actions within the system. Implementing the latest patches is crucial to mitigate the risks associated with this privilege escalation.

Affected Version(s)

Azure CycleCloud 8.9.1 1.0.0 < 8.9.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.