CVE-2026-26148CWE-454
Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
High · published March 10, 2026
What it is
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
The record
Technical detail
- CVSS v3.1
- 8.1 · HIGH
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
- CVSS v4.0
- Not supplied
- EPSS
- 0.00359 · 29.0th percentile
- Weakness
- CWE-454 · External Initialization of Trusted Variables or Data Stores
- Published
- 2026-03-10T17:05Z
EPSS history
Timeline