Elevation of Privileges in Microsoft Azure SRE Agent
CVE-2026-69435

9.6CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 October 2026

What is CVE-2026-69435?

A vulnerability in the Azure SRE Agent allows an authorized attacker to exploit missing authorization checks, enabling them to elevate their privileges on the network. This situation can lead to unauthorized access and manipulation of critical resources within Azure environments, potentially compromising sensitive data and overall system integrity.

Affected Version(s)

Azure SRE Agent -

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.