CVE-2026-62895

8.8

Microsoft · Azure Arc SQL Server Extension

A permissive cross-domain policy in the Microsoft Azure Arc SQL Server Extension allows an unauthenticated, remote attacker to elevate privileges over a network.

Executive summary

This high-severity vulnerability in the Microsoft Azure Arc SQL Server Extension allows unauthenticated attackers to elevate privileges, potentially leading to full system compromise.

Vulnerability

The vulnerability arises from a permissive cross-domain policy that fails to restrict interaction with untrusted domains. An unauthenticated attacker can exploit this configuration to bypass security controls and achieve unauthorized privilege escalation.

Business impact

Successful exploitation of this flaw poses a critical risk to organizational data integrity and system availability. By gaining elevated privileges, an attacker could potentially access sensitive SQL databases, manipulate data, or execute arbitrary commands within the environment. Given the CVSS score of 8.8, this vulnerability represents a significant threat that could result in substantial unauthorized access and operational disruption.

Remediation

Immediate Action: Update the Microsoft Azure Arc SQL Server Extension to version 1.1.3518.465 or later immediately to resolve the cross-domain policy flaw.

Proactive Monitoring: Review system and network access logs for unusual cross-domain requests or unauthorized attempts to interface with the Azure Arc extension.

Compensating Controls: Implement strict network segmentation and egress filtering to prevent the extension from communicating with untrusted or unauthorized external domains.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The elevated privilege risk associated with this vulnerability necessitates an urgent patching cycle. Security teams should prioritize updating all instances of the Azure Arc SQL Server Extension to the identified fixed version to eliminate the underlying cross-domain policy defect and secure the management interface.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources