Vulnerability Details CVE-2026-47299
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 58.4%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2026-47299
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.32.6
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.33.1
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.33.4
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.34.5
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.35.1
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.35.4
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.35.5
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.35.6
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.35.7
-
cpe:2.3:a:microsoft:azure_monitor_agent:1.35.8