ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 215/216 feeds/APIs · 387/387 docs · synced 00:17 UTC Customize Public modeDiscuss ChangeIntel on Discord

Azure SRE Agent Elevation of Privilege Vulnerability

Assessment

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

Severity
Critical
CVSS base score
9.6CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
Impact
Elevation of Privilege
EPSS, next 30 days
Not scored yet
Public exploit code
No Nuclei template lists it
Exploitability
Not assessed
Publicly disclosed
No
Customer action
Not required (service-side fix)
Component
Azure SRE Agent
Weakness
CWE-918: Server-Side Request Forgery (SSRF)
Issued by
Microsoft
Published
8 Oct 2026 · October 2026
Last revised
8 Oct 2026

Updates that fix it

0 KBs

No KB listed

MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.

Affected products

Azure
1 affected product
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 9 Oct 00:17 UTC · 215 of 216 readable · documentation 387/387 current