CVE-2026-47299
Published Aug 11, 2026Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
- evidence mentions
- 3
- Buzz score
- 21.9
Vendor/product archive
14 CVEs tagged to microsoft / azure_monitor_agent — 0 Critical, 13 High, 1 Medium, 0 Low, 0 Unrated.
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability