CVE-2026-62895

Summary

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftAzure Arc SQL Server Extension1.0.0.0 < 1.1.3518.465affected

Weaknesses

  • CWE-942: CWE-942: Permissive Cross-domain Policy with Untrusted Domains
  • CWE-1390: CWE-1390: Weak Authentication
  • CWE-89: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

References