External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
History

Tue, 10 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
Title Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Ad Ssh Login Extension For Linux
Weaknesses CWE-454
CPEs cpe:2.3:a:microsoft:azure_ad_ssh_login_extension_for_linux:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Ad Ssh Login Extension For Linux
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-03-10T19:01:25.212Z

Reserved: 2026-02-11T16:24:51.135Z

Link: CVE-2026-26148

cve-icon Vulnrichment

Updated: 2026-03-10T18:00:55.416Z

cve-icon NVD

Status : Received

Published: 2026-03-10T18:18:43.270

Modified: 2026-03-10T18:18:43.270

Link: CVE-2026-26148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.