A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-26147

CVE-2026-26147: Azure Stack HCI Information Disclosure

CVE-2026-26147 is an information disclosure vulnerability in Microsoft Azure Stack HCI caused by improper input validation in Azure Compute Gallery. This article covers the technical details, affected versions, and mitigation.

Published: May 28, 2026

CVE-2026-26147 Overview

CVE-2026-26147 is an information disclosure vulnerability in Azure Compute Gallery affecting Microsoft Azure Stack HCI. The flaw stems from improper input validation [CWE-20], allowing an authorized attacker to disclose sensitive information over a network. Microsoft published the advisory through the Microsoft Security Response Center (MSRC).

The vulnerability requires low privileges and no user interaction. It carries a scope change, meaning successful exploitation can impact resources beyond the vulnerable component. Confidentiality impact is rated high, while integrity and availability are not affected.

Critical Impact

An authenticated attacker with low privileges can exploit improper input validation in Azure Compute Gallery to read sensitive information across trust boundaries within Azure Stack HCI environments.

Affected Products

  • Microsoft Azure Stack HCI
  • Azure Compute Gallery component
  • Deployments referencing cpe:2.3:a:microsoft:azure_stack_hci

Discovery Timeline

  • 2026-05-22 - CVE-2026-26147 published to NVD
  • 2026-05-27 - Last updated in NVD database

Technical Details for CVE-2026-26147

Vulnerability Analysis

The vulnerability resides in the Azure Compute Gallery service used by Azure Stack HCI to manage and distribute virtual machine images, application definitions, and related artifacts. Improper input validation [CWE-20] in request handling permits an authorized caller to submit crafted input that the service processes without adequate sanitization. The resulting behavior exposes data the caller should not be able to read.

Because the CVSS scope is changed, the disclosure crosses a security boundary. An attacker operating within one authorization context can retrieve information belonging to a different context managed by the same gallery service. This pattern is consistent with multi-tenant or shared-resource cloud services where input parsing dictates which records are returned.

Root Cause

The root cause is missing or insufficient validation of attacker-controlled input within Azure Compute Gallery request processing. When validation logic fails to constrain identifiers, filters, or query parameters, the service returns data outside the caller's intended scope. Microsoft has not published implementation specifics, and no public proof-of-concept exists.

Attack Vector

The attack vector is network-based. An attacker must hold valid credentials with low privileges in the target Azure Stack HCI environment. Exploitation does not require user interaction or social engineering. Once authenticated, the attacker sends crafted requests to the Azure Compute Gallery API and parses responses for disclosed material such as image metadata, configuration details, or other gallery-managed information.

No exploit code is publicly available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the EPSS score reflects a low predicted likelihood of exploitation in the near term.

Detection Methods for CVE-2026-26147

Indicators of Compromise

  • Unexpected Azure Compute Gallery API calls originating from low-privilege service principals or user accounts
  • Repeated GET operations against gallery image, version, or application resources outside the caller's normal scope
  • Anomalous enumeration patterns against Microsoft.Compute/galleries resource providers in Azure activity logs

Detection Strategies

  • Review Azure Activity Logs and Azure Resource Manager audit trails for gallery read operations performed by accounts that do not typically access those resources
  • Correlate Microsoft Entra ID sign-in events with subsequent gallery queries to identify suspicious session activity
  • Baseline expected gallery access per role and alert on deviations such as cross-subscription or cross-resource-group reads

Monitoring Recommendations

  • Enable diagnostic settings on Azure Compute Gallery resources and forward logs to a central SIEM for retention and analysis
  • Monitor authorization failures and partial-success responses from gallery endpoints that may indicate probing
  • Track service principal and managed identity behavior for unusual gallery API consumption volumes

How to Mitigate CVE-2026-26147

Immediate Actions Required

  • Apply the security update referenced in the Microsoft CVE-2026-26147 Advisory as soon as it is available for your Azure Stack HCI deployment
  • Audit role assignments on Azure Compute Gallery resources and remove unnecessary read or contributor permissions
  • Rotate credentials and review access tokens for accounts that interact with gallery resources

Patch Information

Microsoft has published guidance through the Microsoft CVE-2026-26147 Advisory. Administrators should consult the advisory for build numbers, update channels, and applicability to specific Azure Stack HCI versions. Apply patches through standard Azure Stack HCI update workflows.

Workarounds

  • Enforce least-privilege RBAC on Microsoft.Compute/galleries resources, granting only the minimum role required for each principal
  • Restrict network access to management endpoints using Azure Private Link, service endpoints, or firewall rules where supported
  • Require conditional access policies and multi-factor authentication for any identity that can call gallery APIs
bash
# Configuration example: review role assignments on a Compute Gallery resource
az role assignment list \
  --scope "/subscriptions/<sub-id>/resourceGroups/<rg>/providers/Microsoft.Compute/galleries/<gallery>" \
  --output table

# Remove an unnecessary assignment
az role assignment delete \
  --assignee <principal-id> \
  --role "Reader" \
  --scope "/subscriptions/<sub-id>/resourceGroups/<rg>/providers/Microsoft.Compute/galleries/<gallery>"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeInformation Disclosure

  • Vendor/TechMicrosoft Azure Stack Hci

  • SeverityHIGH

  • CVSS Score7.7

  • EPSS Probability0.13%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-20
  • Vendor Resources
  • Microsoft CVE-2026-26147 Advisory
  • Related CVEs
  • CVE-2024-49060: Azure Stack HCI Privilege Escalation
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English