Vulnerability  ·  2026-10-10

Azure SRE Agent missing authorization allows network privilege escalation (CVSS 9.6)

VulnerabilityHigh impactGlobalCVE-2026-69435
Verified via NVD REST API (published 2026-10-08): missing authorization in Microsoft's Azure SRE Agent lets an authorised attacker elevate privileges over a network (CVSS 9.6, scope changed, C/H:C/I). NVD tags it an exclusively-hosted Microsoft service.
AI-relevant as agentic infrastructure: Microsoft's SRE Agent is an automation/ops agent operating inside Azure with network command-and-control; a missing-authorization flaw that lets a low-privileged authorised user climb privileges on the agent's network scope can translate into control of the ops automation layer itself.
An authorised (low-privilege) Azure-network user exploits missing authorization in the SRE Agent to elevate privileges over the network, gaining high confidentiality/integrity impact on the agent's managed scope.
Microsoft Azure SRE Agent (exclusively-hosted Microsoft Azure service)
No customer action — exclusively-hosted service remediated by Microsoft. Track via MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69435
NVD CVE-2026-69435Microsoft MSRC
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →