CVE-2026-26117: Hijacking Azure Arc on Windows for Local Privilege Escalation & Cloud Identity Takeover
Weβve disclosed CVE-2026-26117 affecting Azure Arc on Windows: a high severity local privilege escalation that can also be used to take over the machineβs cloud identity.
In practical terms, this means a low-privileged user on an Arc-joined Windows host may be able to escalate to higher privileges and then abuse the Arc identity context to pivot into Azure.
If youβre running Azure Arcβjoined Windows machines and your Arc Agent services are below v1.61, assume youβre impacted update to v1.61.
[link] [comments]