Microsoft disclosed a CVSS 9.3 path traversal flaw in Azure Arc that lets an unauthenticated attacker elevate privileges over a network with no user interaction.
What Is It
CVE-2026-70009 is an improper limitation of a pathname to a restricted directory, classic path traversal, tracked as CWE-22, in Microsoft Azure Arc. Per the vendor description, the flaw "allows an unauthorized attacker to elevate privileges over a network."
The CVE was published by Microsoft's MSRC ([email protected]) on 2026-09-17 and currently sits in NVD with a vulnerability status of Received, meaning NVD enrichment is not yet complete. The only metrics and affected-product data available come from Microsoft as the primary CNA.
Why It Matters
Microsoft scored the issue 9.3 CRITICAL under CVSS 3.1, with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N.
The exploitability subscore is a maximum 3.9. Every precondition an attacker would normally need is absent: the attack is reachable over the network, complexity is low, no privileges are required, and no user interaction is needed. Scope is Changed, meaning successful exploitation reaches beyond the vulnerable component's security boundary; which, combined with High integrity impact, is what pushes an otherwise moderate impact profile into critical territory. Confidentiality impact is Low and availability impact is None.
CVE-2026-70009 does not appear in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-17, and no KEV-driven remediation deadline applies. Absence from the catalog reflects what CISA has published to date; there is no public confirmation of exploitation, which is not the same as confirmation that the flaw has not been exploited.
What's Vulnerable
Microsoft lists a single affected product:
- Vendor: Microsoft
- Product: Azure ARC
- Affected version:
-(no version enumeration provided)
No CPE entries are published in the NVD record. Microsoft tagged the CVE exclusively-hosted-service, indicating the vulnerability resides in a Microsoft-operated cloud service rather than in software customers deploy and version themselves.
Patch Status
The available data contains no patch version, KB number, mitigation, or workaround. No required action or remediation deadline is specified, as the CVE is not listed in the KEV catalog. Microsoft's authoritative servicing status is published in the MSRC update guide entry linked below.
Sources
- Microsoft MSRC Update Guide; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009
- NVD, CVE-2026-70009, https://nvd.nist.gov/vuln/detail/CVE-2026-70009
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog