CVE Vulnerabilities

CVE-2026-26148

External Initialization of Trusted Variables or Data Stores

Published: Mar 10, 2026 | Modified: Mar 13, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

Weakness

The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors.

Affected Software

NameVendorStart VersionEnd Version
Azure_ad_ssh_login_extension_for_linuxMicrosoft1.0.0 (including)1.0.033370002 (excluding)

Potential Mitigations

References