CVE-2026-42822 Details
Description
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
A vulnerability allowing improper authentication in Azure Local Disconnected Operations (ALDO) has been identified, enabling unauthorized attackers to elevate privileges over a network. This issue affects customers with access to the ALDO environment.
Customers using Azure Local Disconnected Operations must update to version 2604 or later. This update is not available as a standalone patch and must be applied as a full system update through the Azure portal. ALDO updates are only accessible to approved customers via allow-listing.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft azure local | < 2604.2.25645 |
CPE
Remediation
| |
| microsoft azure resource manager | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | Initial Analysis | [email protected] |
| May 18, 2026 | New CVE Received | [email protected] |