{
  "document" : {
    "aggregate_severity" : {
      "text" : "hoch"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "Azure ist eine Cloud Computing-Plattform von Microsoft.\r\nMicrosoft Entra ID (früher Azure Active Directory) ist ein cloudbasierter Identitäts- und Zugriffsverwaltungsdienst von Microsoft.\r\nDie Azure-Befehlszeilenschnittstelle (Command-Line Interface, CLI) setzt sich aus Befehlen zum Erstellen und Verwalten von Azure-Ressourcen zusammen. Die Azure CLI ist in allen Azure-Diensten verfügbar.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft Entra und Microsoft Azure CLI ausnutzen, um sich als andere Benutzer auszugeben, unberechtigt auf geschützte Daten und Funktionen zuzugreifen und diese zu verändern, erhöhte Berechtigungen bis hin zu SYSTEM-Rechten zu erlangen, beliebige Systembefehle bzw. Code mit den Rechten privilegierter Benutzer auszuführen sowie vertrauliche Informationen offenzulegen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Windows",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2026-3265 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3265.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2026-3265 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3265"
    }, {
      "category" : "external",
      "summary" : "Microsoft Leitfaden für Sicherheitsupdates",
      "url" : "https://msrc.microsoft.com/update-guide/"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-69857",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69857"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-81349",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81349"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-83711",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-84003",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-84003"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-83941",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83941"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-62916",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-83948",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83948"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-70352",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-77909",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77909"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-69854",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69854"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-62895",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62895"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-62906",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62906"
    } ],
    "source_lang" : "en-US",
    "title" : "Microsoft Azure, Entra und Azure CLI : Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2026-09-08T22:00:00.000+00:00",
      "generator" : {
        "date" : "2026-09-09T10:59:18.884+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.6.0"
        }
      },
      "id" : "WID-SEC-W-2026-3265",
      "initial_release_date" : "2026-09-08T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2026-09-08T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      } ],
      "status" : "final",
      "version" : "1"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_version",
          "name" : "HDInsight",
          "product" : {
            "name" : "Microsoft Azure HDInsight",
            "product_id" : "T059238",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:hdinsight"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "CycleCloud 8.9.2",
          "product" : {
            "name" : "Microsoft Azure CycleCloud 8.9.2",
            "product_id" : "T059241",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:cyclecloud_8.9.2"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Spring Cloud Azure",
          "product" : {
            "name" : "Microsoft Azure Spring Cloud Azure",
            "product_id" : "T059242",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:spring_cloud_azure"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Arc SQL Server Extension",
          "product" : {
            "name" : "Microsoft Azure Arc SQL Server Extension",
            "product_id" : "T059243",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:arc_sql_server_extension"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Azure"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "Authentication Library (MSAL) for Node.js",
          "product" : {
            "name" : "Microsoft Entra Authentication Library (MSAL) for Node.js",
            "product_id" : "T059289",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:entra:authentication_library_%28msal%29_for_node.js"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Entra"
      } ],
      "category" : "vendor",
      "name" : "Microsoft"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2026-62895",
    "product_status" : {
      "known_affected" : [ "T059241", "T059243", "T059242", "T059289", "T059238" ]
    },
    "release_date" : "2026-09-08T22:00:00.000+00:00",
    "title" : "CVE-2026-62895"
  }, {
    "cve" : "CVE-2026-69854",
    "product_status" : {
      "known_affected" : [ "T059241", "T059243", "T059242", "T059289", "T059238" ]
    },
    "release_date" : "2026-09-08T22:00:00.000+00:00",
    "title" : "CVE-2026-69854"
  }, {
    "cve" : "CVE-2026-77909",
    "product_status" : {
      "known_affected" : [ "T059241", "T059243", "T059242", "T059289", "T059238" ]
    },
    "release_date" : "2026-09-08T22:00:00.000+00:00",
    "title" : "CVE-2026-77909"
  }, {
    "cve" : "CVE-2026-81349",
    "product_status" : {
      "known_affected" : [ "T059241", "T059243", "T059242", "T059289", "T059238" ]
    },
    "release_date" : "2026-09-08T22:00:00.000+00:00",
    "title" : "CVE-2026-81349"
  }, {
    "cve" : "CVE-2026-83948",
    "product_status" : {
      "known_affected" : [ "T059241", "T059243", "T059242", "T059289", "T059238" ]
    },
    "release_date" : "2026-09-08T22:00:00.000+00:00",
    "title" : "CVE-2026-83948"
  }, {
    "cve" : "CVE-2026-84003",
    "product_status" : {
      "known_affected" : [ "T059241", "T059243", "T059242", "T059289", "T059238" ]
    },
    "release_date" : "2026-09-08T22:00:00.000+00:00",
    "title" : "CVE-2026-84003"
  } ]
}