
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-42830 is an Untrusted Search Path (CWE-426) vulnerability in Microsoft Azure Monitor Agent that allows an authorized local attacker with low privileges to elevate privileges locally. It affects Azure Monitor Agent versions prior to 1.42.0. The vulnerability was published on May 12, 2026, as part of Microsoft's May 2026 Patch Tuesday, and a patch was made available the same day. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Microsoft (MSRC Advisory, GitHub Advisory).
The vulnerability is classified as CWE-426 (Untrusted Search Path), meaning Azure Monitor Agent searches for critical resources using an externally-supplied or manipulable search path that can be redirected to resources outside the agent's direct control. An attacker with local, low-privilege access can manipulate the search path (e.g., via PATH environment variable hijacking, mapped to MITRE ATT&CK T1574.007) to cause the agent to load a malicious resource, resulting in privilege escalation. The attack requires no user interaction and has low complexity, but does require an existing local account on the affected system. The scope is marked as "Changed," indicating the impact crosses security boundaries beyond the vulnerable component itself (GitHub Advisory, MSRC Advisory).
Successful exploitation allows a low-privileged local user to escalate privileges on systems running Azure Monitor Agent, resulting in high integrity impact across process boundaries (scope changed). While confidentiality and availability are not directly impacted per the CVSS scoring, an attacker gaining elevated privileges could subsequently modify system configurations, tamper with monitoring data, or use the elevated access as a foothold for further lateral movement within the environment (MSRC Advisory, GitHub Advisory).
cmd.exe, powershell.exe, or other shells) with elevated privileges; processes running under SYSTEM or elevated context originating from the agent.Microsoft has released a patched version of Azure Monitor Agent; organizations should update to version 1.42.0 or later to remediate this vulnerability. As a workaround, restrict local user access to systems running Azure Monitor Agent and enforce the principle of least privilege for all local accounts. Additionally, review and lock down PATH environment variable configurations and directory permissions to prevent unauthorized write access to directories in the agent's search path (MSRC Advisory, GitHub Advisory).
CVE-2026-42830 was disclosed as part of Microsoft's May 2026 Patch Tuesday, which addressed 120 vulnerabilities total. Coverage from security outlets including BleepingComputer, Rapid7, Zero Day Initiative, Sophos, and CyberSecurityNews noted the patch release but did not highlight this specific CVE as particularly critical compared to the 29 critical RCE flaws also addressed in the same update cycle. Community and researcher attention was relatively limited given the medium severity rating and absence of a public PoC (BleepingComputer, Rapid7, ZDI).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."