CVE-2026-24302 Azure Arc Elevation of Privilege Vulnerability
Published February 6, 2026
Information published.
Published February 6, 2026
Information published.
Published January 30, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 30, 2026
Corrected Download links in the Security Updates table. This is an informational change only.
Published January 28, 2026
Updated FAQ information. This is an informational change only.
Published January 24, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 23, 2026
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.
Published January 23, 2026
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Published January 23, 2026
Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
Published January 23, 2026
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Published January 23, 2026
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.