CVE-2026-26148

8.1

Microsoft · Azure AD SSH Login extension for Linux

A vulnerability in the Azure AD SSH Login extension for Linux allows unauthorized local attackers to elevate privileges by exploiting external initialization of trusted variables.

Executive summary

A critical privilege escalation vulnerability in the Microsoft Azure AD SSH Login extension for Linux allows unauthenticated local attackers to gain elevated system access.

Vulnerability

The flaw, classified as CWE-454, involves the external initialization of trusted variables or data stores within the extension. This permits an unauthenticated attacker with local access to manipulate these variables and achieve a local privilege escalation.

Business impact

The ability for an unauthenticated local attacker to elevate privileges poses a severe threat to system integrity and confidentiality. By gaining unauthorized elevated access, an attacker could potentially bypass security controls, access sensitive data, or establish persistent control over the affected Linux infrastructure. With a CVSS score of 8.1, this vulnerability is categorized as high severity and requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Update the Microsoft Azure AD SSH Login extension for Linux to version 1.0.033370002 or later as specified in the official Microsoft security update guide.

Proactive Monitoring: Review system authentication and sudo logs for unauthorized privilege elevation attempts or unexpected configuration changes related to the extension.

Compensating Controls: Ensure that physical and logical access to the host server is strictly restricted to authorized personnel to limit the possibility of local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise through privilege escalation, organizations utilizing the Azure AD SSH Login extension for Linux must prioritize this update. Administrators should verify the version of the extension across all deployed Linux instances and apply the necessary patches immediately to neutralize this security risk.

More Microsoft CVEs

Sources