CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-33109

CVSS 9.9v3.1pub. 2026-05-07upd. 2026-05-08

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The vulnerability consists of improper access control (CWE-284) in the Azure Managed Instance for Apache Cassandra service. An attacker with basic network privileges can, without user interaction and with low attack complexity, exploit this vulnerability to execute arbitrary code in the context of the service. The network attack vector and lack of requirement for high privileges significantly lower the barrier to entry for a potential exploit. The scope of the vulnerability extends beyond the directly attacked component (Scope: Changed), which may indicate the possibility of impact on other resources in the cloud environment.

Impact

An attacker can remotely execute code on infrastructure managed by Microsoft Azure, leading to complete loss of confidentiality, integrity, and availability of data stored in the service, and potentially enabling lateral movement within the cloud environment.

Mitigation & patch

Apply patches available from the vendor according to the references. It is recommended to check the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33109 for current instructions regarding updates or workarounds. In Microsoft Azure cloud environments, managed service updates may be applied automatically — the status of your environment should be verified.

Who is affected

Microsoft Azure Managed Instance for Apache Cassandra — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Azure Managed Instance For Apache Cassandra

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65770CRITICAL10.0same product

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance f...

CVE-2026-33844CRITICAL9.0PL ✓same product

Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra – RCE

CVE-2024-38175CRITICAL9.6PL ✓same product

Nieprawidłowa kontrola dostępu w Azure Managed Instance for Apache Cassandra — privilege escalation

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)