Advisory · CVE-2026-69435
Missing authorization in Azure SRE Agent lets an authorized attacker elevate privileges
Azure SRE Agent had a missing authorization check that an authenticated attacker could abuse over the network to elevate privileges, rated critical at CVSS 9.6.
- Vendor
- Microsoft
- Product
- Azure SRE Agent
- Identifier / CWE
- CVE-2026-69435
CWE-918 - Action timing
- Immediate
Explain it like I’m five
The agent checked that you are allowed in the building but never checked which rooms your keycard opens. Someone with any valid keycard could walk into the server room.
- 01Attacker authenticates
An attacker with valid low-privileged credentials logs into Azure SRE Agent.
- 02Missing check
A request reaches a function where the authorization check is absent.
- 03Privileges elevated
The attacker performs actions beyond their assigned role across the network scope.
What happened
Microsoft disclosed CVE-2026-69435 in Azure SRE Agent on October 8, 2026. The flaw is missing authorization: an attacker with low-privileged authenticated access can elevate privileges over the network. It scores 9.6 on CVSS 3.1 (network, low complexity, changed scope, high confidentiality and integrity impact). NVD marks the entry as exclusively a hosted-service issue, so the fix lands on Microsoft’s side.
What to do
- No customer patch exists to apply; Microsoft remediates the service.
- Check who in your tenant has access to Azure SRE Agent and confirm least privilege is actually enforced in practice.
- Review Azure activity logs for role or permission changes you cannot explain, especially around October 8, 2026.
- If the agent touches sensitive infrastructure, rotate any credentials or tokens it could have reached.
- Watch for a Microsoft post-incident notice with exposure details.
Management note
A service your team runs with production-level access had a privilege check missing, and the only remediation is the vendor’s. The honest response is verification: prove nobody used the gap while it was open, and tighten who gets into the agent going forward.