CVE-2026-26148
Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected products
Microsoft · Microsoft Azure AD SSH Login extension for LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →