CVE-2026-69399EUVD-2026-8258617.09.2026, 23:18Azure Arc Elevation of Privilege VulnerabilityConfused DeputyEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTPrimary10 CRITICALNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAwaiting analysisThis vulnerability is currently awaiting analysis.Base ScoreCVSS 3.xEPSS ScorePercentile: 41.44%Common Weakness EnumerationCWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.Vulnerability Media Exposure[GERMAN] Microsoft Azure: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft Azure Cosmos DB, Microsoft Entra und Microsoft Azure CLI ausnutzen, um seine Privilegien zu erhöhen, um falsche Informationen darzustellen, um Informationen offenzulegen und um beliebigen Programmcode auszuführen.Published: 2026-09-17T22:00:00+00:00Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69399