CVE-2026-62895

Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-08 18:18

Updated : 2026-09-10 21:17


NVD link : CVE-2026-62895

Mitre link : CVE-2026-62895

CVE.ORG link : CVE-2026-62895


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CWE-942

Permissive Cross-domain Security Policy with Untrusted Domains

CWE-1390

Weak Authentication