What happened
Verified via NVD REST API (published 2026-10-08): missing authorization in Microsoft's Azure SRE Agent lets an authorised attacker elevate privileges over a network (CVSS 9.6, scope changed, C/H:C/I). NVD tags it an exclusively-hosted Microsoft service.
Why it matters
AI-relevant as agentic infrastructure: Microsoft's SRE Agent is an automation/ops agent operating inside Azure with network command-and-control; a missing-authorization flaw that lets a low-privileged authorised user climb privileges on the agent's network scope can translate into control of the ops automation layer itself.
Attack vector
An authorised (low-privilege) Azure-network user exploits missing authorization in the SRE Agent to elevate privileges over the network, gaining high confidentiality/integrity impact on the agent's managed scope.
Affected systems
Microsoft Azure SRE Agent (exclusively-hosted Microsoft Azure service)
Mitigation
No customer action — exclusively-hosted service remediated by Microsoft. Track via MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69435