CVE-2026-81349Important
Azure HDInsight Ambari Elevation of Privilege Vulnerability
Assessment
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
- Severity
- Important
- CVSS base score
- 7.2CVSS:3.1/
AV:N/ AC:L/ PR:H/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:P/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 1.0%Higher than 61.6% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Not assessed
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Azure HDInsights
- Weakness
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Issued by
- Microsoft
- Published
- 8 Sep 2026 · September 2026
- Last revised
- 8 Sep 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Azure1 affected product
- Azure HDInsight