CVE-2026-47632ImportantRevised 18 Aug
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Assessment
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
- Severity
- Important
- CVSS base score
- 8.8CVSS:3.1/
AV:A/ AC:L/ PR:N/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.5%Higher than 40% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Azure Connected Machine Agent
- Weakness
- CWE-295: Improper Certificate Validation
- Issued by
- Microsoft
- Published
- 14 Jul 2026 · July 2026
- Last revised
- 18 Aug 2026Corrected the affected product from Azure Monitor Agent Metrics Extension to Azure Connected Machine Agent and updated the Security Updates table. This is an informational change only.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Azure1 affected product
- Azure Connected Machine Agent