CVE-2026-40381 | Microsoft Azure Connected Machine Agent prior 1.63 access control
A vulnerability classified as critical has been found in Microsoft Azure Connected Machine Agent. Affected by this vulnerability is an unknown functionality. This manipulation causes improper access controls.
This vulnerability is tracked as CVE-2026-40381. The attack is restricted to local execution. No exploit exists.
It is recommended to upgrade the affected component.