
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32204 is a local privilege escalation vulnerability in Microsoft Azure Monitor Agent caused by external control of file name or path (CWE-73). An authorized attacker with low-privilege local access can manipulate file paths to elevate privileges on the affected system. The vulnerability affects Azure Monitor Agent versions prior to 1.14.0 and was disclosed on May 12, 2026, as part of Microsoft's May 2026 Patch Tuesday, which addressed 120 flaws (BleepingComputer, MSRC). It carries a CVSS v3.1 base score of 7.8 (High) (MSRC).
The root cause is classified as CWE-73 (External Control of File Name or Path), where the Azure Monitor Agent fails to adequately restrict or validate file name or path inputs supplied by a local user. This allows an attacker to influence which files the agent accesses or executes, potentially redirecting operations to attacker-controlled paths — a technique consistent with path interception (MITRE ATT&CK T1574.007) or dynamic linker hijacking (T1574.006) (Feedly). Exploitation requires only low-privilege local access and no user interaction, making it straightforward for any authenticated local user on an affected system. No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation allows a low-privileged local attacker to elevate privileges to a higher level on the compromised host, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary code in the context of the Azure Monitor Agent process, potentially gaining SYSTEM-level or elevated service account access. This could enable further lateral movement within the environment, access to sensitive monitoring data, or disruption of monitoring capabilities (Feedly, MSRC).
Microsoft released a security update for Azure Monitor Agent on May 12, 2026 (Patch Tuesday), addressing this vulnerability in version 1.14.0 and later (MSRC, Feedly). Organizations should update Azure Monitor Agent to version 1.14.0 or above as the primary remediation step. As interim mitigations, administrators should implement strict access controls to limit which low-privilege users can interact with systems running Azure Monitor Agent, and monitor file system operations for suspicious path manipulations associated with the agent process (Feedly).
The vulnerability was covered as part of broader May 2026 Patch Tuesday roundups by multiple security outlets. BleepingComputer, Rapid7, Sophos, Zero Day Initiative, and Lansweeper all noted the 120-vulnerability release but did not single out CVE-2026-32204 as a particularly critical or notable flaw compared to others in the batch (BleepingComputer, Rapid7, Sophos, ZDI). No significant independent researcher commentary or social media discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."