Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 13 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Title | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft azure Connected Machine Agent |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Connected Machine Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-05-15T17:13:29.460Z
Reserved: 2026-04-11T23:06:15.616Z
Link: CVE-2026-40381
Updated: 2026-05-13T09:58:19.350Z
Status : Awaiting Analysis
Published: 2026-05-12T18:17:16.970
Modified: 2026-05-13T15:34:52.573
Link: CVE-2026-40381
No data.
OpenCVE Enrichment
Updated: 2026-05-12T20:30:23Z