CVE-2026-26117 | Microsoft Arc Enabled Servers Azure Connected Machine Agent authentication bypass
A vulnerability classified as critical has been found in Microsoft Arc Enabled Servers. Affected is an unknown function of the component Azure Connected Machine Agent. This manipulation causes authentication bypass using alternate channel.
This vulnerability is handled as CVE-2026-26117. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to install a patch to address this issue.