A server-side request forgery (SSRF) flaw in Microsoft's Azure SRE Agent lets an attacker who already has low-level access elevate privileges over a network. It is rated CVSS 9.6 (Critical).
What Is It
CVE-2026-69435 is a privilege escalation vulnerability in Azure SRE Agent. Microsoft's description says it "allows an authorized attacker to elevate privileges over a network." The record lists the weakness as CWE-918 (Server-Side Request Forgery). Microsoft ([email protected]) assigned the CVE, and NVD published it on 2026-10-08. NVD's status is "Received," so NVD has not finished its own analysis.
Why It Matters
Microsoft scores this as CVSS 3.1 9.6 (CRITICAL) with vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N:
- It can be reached over the network and has low attack complexity
- It needs only low privileges and no user interaction
- Scope changed: the impact can reach resources beyond the vulnerable component
- It has high impact on confidentiality and integrity and no impact on availability
The attacker needs some existing access first. With that access, the flaw is easy to exploit and can affect other resources.
Exploitation status: this CVE has no entry in CISA's Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. None of the supplied sources report exploitation in the wild.
What's Vulnerable
- Vendor: Microsoft
- Product: Azure SRE Agent
- Versions: listed as "-" (affected). The record gives no specific version ranges and no CPE entries.
Microsoft tagged the CVE exclusively-hosted-service. That means Azure SRE Agent runs only as a service Microsoft hosts. Customers do not deploy it themselves.
Patch Status
The supplied records give no patch release, fixed version or required customer action. CISA has set no remediation deadline because the CVE is not in KEV. Since Microsoft hosts the service, the fix is expected on Microsoft's side, but the supplied data does not confirm that. Azure SRE Agent users should check the MSRC advisory for current remediation details and any steps they need to take. Exploitation requires an attacker who is already authorized, so users should also review who has access to their Azure SRE Agent resources.