CVE-2026-26141

7.8

Microsoft · Azure Automation Hybrid Worker Windows Extension

Improper authentication in the Microsoft Azure Automation Hybrid Worker Windows Extension allows a locally authenticated attacker to elevate privileges.

Executive summary

A privilege escalation vulnerability in the Microsoft Azure Automation Hybrid Worker Windows Extension poses a significant risk to local system integrity and security.

Vulnerability

This vulnerability, categorized as CWE-287, involves improper authentication mechanisms within the extension. It allows an attacker who already possesses low-level local privileges to bypass authentication controls and achieve unauthorized elevation of privilege.

Business impact

The ability for a local user to elevate privileges to a higher level of authority could lead to a total compromise of the affected host. This risk is reflected in the CVSS score of 7.8, which indicates a High severity level. Unauthorized access at this level may result in data exfiltration, the installation of malicious software, or complete system takeover, causing significant operational disruption.

Remediation

Immediate Action: Update the Microsoft Azure Automation Hybrid Worker Windows Extension to version 1.3.74 or later immediately.

Proactive Monitoring: Review local system logs for unusual account activity or unauthorized attempts to access administrative functions.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local user accounts to limit the potential blast radius of a compromised account.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for full administrative compromise of the affected host, organizations should prioritize patching the Azure Automation Hybrid Worker Windows Extension. Failure to remediate this vulnerability leaves systems susceptible to privilege escalation attacks that could bypass existing security boundaries. Apply the vendor-provided update as soon as possible to mitigate this risk.

More Microsoft CVEs

Sources