CVE-2026-26148 Details
Description
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
A vulnerability in the Azure AD SSH Login extension for Linux has been identified, allowing unauthorized attackers to elevate privileges locally. This issue arises from the external initialization of trusted variables or data stores in Azure Entra ID.
To address this vulnerability, users can update the Azure AD SSH Login extension for Linux using their distribution's package manager. Systems with the extension already installed have packages.microsoft.com configured automatically. Users should run 'sudo apt update aadsshlogin' for Ubuntu or Debian, 'sudo dnf update aadsshlogin' for RHEL-based distributions, or 'sudo zypper update aadsshlogin' for SUSE-based distributions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26148 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-454 | External Initialization of Trusted Variables or Data Stores | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft azure ad ssh login extension for linux | >= 1.0.0, < 1.0.033370002 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 13, 2026 | Initial Analysis | [email protected] |
| Mar 10, 2026 | New CVE Received | [email protected] |