CVE-2026-24304
Microsoft Azure Resource Manager has a critical flaw that lets an attacker with some access rights gain higher privileges across the network. The weakness is an improper access control that can be abused by someone who already has limited permissions. It can lead to full control over Azure resources.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Microsoft Azure Resource Manager (all versions)
Real-world impact
An attacker who can already access Azure Resource Manager can use this flaw to increase their privileges, potentially taking full control of the Azure environment and all resources within it.
Why this severity
The CVSS score of 9.9 reflects a network‑based attack that requires low effort and low privileges, but the impact is complete compromise of confidentiality, integrity, and availability. The vector shows that the attack can be launched remotely, needs only low privileges, and the user interface is not required, making it highly dangerous.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jan 23, 2026 · Jan 23, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- msrc.microsoft.com/update-guide/vulnerability/…vendor advisory