CVE-2026-58275
Azure DNS has a missing authorization flaw that lets an attacker gain elevated privileges on the network. The vulnerability can be exploited without authentication or user interaction. It is rated critical with a CVSS score of 10.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Azure DNS services (specific versions not listed).
Real-world impact
An attacker could take control of network resources, modify DNS records, and potentially redirect traffic or disrupt services.
Why this severity
The CVSS score is 10 because the flaw allows complete privilege escalation with no authentication, no user interaction, and full control over confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources