CVE-2026-83948

Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.

  • Published Sep 8, 2026
  • CVSS 8.0 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-83948 at the National Vulnerability Database