
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47299 is a command injection vulnerability in the Azure Monitor Agent Linux Extension that allows an authorized attacker with high privileges to elevate privileges over a network. It affects Azure Monitor Agent versions 1.0.0 through 1.42.x on Linux. Microsoft disclosed and patched the vulnerability on August 11, 2026, as part of the August 2026 Patch Tuesday release. It carries a CVSS v3.1 base score of 7.2 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'). An authorized attacker with high-level privileges can craft malicious input that is improperly sanitized by the Azure Monitor Agent on Linux, allowing injected commands to be executed in the agent's context. The attack vector is network-based, requires no user interaction, and has low attack complexity, though it does require pre-existing high-privilege access. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Microsoft MSRC).
Successful exploitation results in a complete compromise of the affected Linux system, with high impact to confidentiality, integrity, and availability. An attacker who already holds high-level authorized access can leverage this vulnerability to execute arbitrary commands and escalate their privileges further within the system. This could enable lateral movement within Azure-connected environments, unauthorized access to monitored data, and disruption of monitoring services (Microsoft MSRC).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of August 2026. The EPSS score is approximately 0.94%, indicating a low near-term probability of exploitation. The NVD SSVC assessment classifies exploitation as 'none' and the vulnerability as not automatable. CVE-2026-47299 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Microsoft MSRC).
Microsoft released a patch on August 11, 2026; organizations should update the Azure Monitor Agent Linux Extension to version 1.43 or later on all affected systems. Prioritize systems running versions 1.0.0 through 1.42.x. As a compensating control, restrict administrative access to Azure Monitor Agent configurations and limit network-level access to the agent's management interfaces. Monitor for suspicious command execution activity in agent logs on affected Linux hosts (Microsoft MSRC).
The vulnerability was noted in the context of Microsoft's August 2026 Patch Tuesday, which addressed approximately 400 security flaws. Coverage appeared across security outlets including BleepingComputer, Rapid7, SANS ISC, and Lansweeper, primarily as part of broader Patch Tuesday roundups rather than dedicated analysis of this specific CVE (BleepingComputer, Rapid7, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."