azure_arc vulnerabilities
CVEs whose affected-version data names the azure_arc package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-70009Critical· 9.3Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Azure ARCEPSS 0.47%via NVD
CVE-2026-69399Critical· 10.0Azure Arc Elevation of Privilege Vulnerability
Azure Arc Elevation of Privilege Vulnerability
▾ MidnightMicrosoft · Azure ARCEPSS 0.49%via NVD
CVE-2026-69555Critical· 10.0Azure Arc Elevation of Privilege Vulnerability
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Azure ARCEPSS 0.44%via CVEORG