CVE-2026-26148CWE-454

Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability

High · published March 10, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
29.0
In the wild
Unconfirmed
What it is

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00359 · 29.0th percentile
Weakness
CWE-454 · External Initialization of Trusted Variables or Data Stores
Published
2026-03-10T17:05Z
EPSS history
Timeline
  • 10 MAR 17:05Z
    Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
    cvelistv5