Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
The flaw consists of improper neutralization of special characters in input data passed to system commands (CWE-77). An attacker, by inducing user interaction (UI:R), can smuggle malicious command sequences that will be executed in the context of Azure Cloud Shell. Due to the changed scope of attack (S:C), the effects may extend beyond the directly attacked component.
An attacker can conduct a spoofing attack, potentially compromising the confidentiality, integrity, and availability of resources in the Azure Cloud Shell environment and related components (all three indicators rated as HIGH in CVSS).
Patches available from the vendor should be applied according to the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35428
Microsoft Azure Cloud Shell — specific versions indicated in the vendor's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMicrosoft Azure Cloud Shell
APPMicrosoftall versions
Related vulnerabilities
SSRF w Microsoft Azure Cloud Shell umożliwia eskalację uprawnień
Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów