CVE-2024-43469
Azure CycleCloud Remote Code Execution Vulnerability
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 1.59%
- CWE
- CWE-94
- Published
- 2024-09-10
- Last modified
- 2026-08-10
Affected products
- Microsoft Azure CycleCloud 8.2.0
- Microsoft Azure CycleCloud 8.0.0
- Microsoft Azure CycleCloud 8.6.0
- Microsoft Azure CycleCloud 8.0.1
- Microsoft Azure CycleCloud 8.0.2
- Microsoft Azure CycleCloud 8.1.0
- Microsoft Azure CycleCloud 8.1.1
- Microsoft Azure CycleCloud 8.2.2
Weakness type
Related vulnerabilities
- CVE-2026-60004 — Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- CVE-2026-76605 — Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2
- CVE-2026-76604 — Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2026-53710 — MCP Context Forge: RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
- CVE-2026-55565 — Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
- CVE-2026-55634 — Pimcore: Remote Code Execution via DataObject Class-Definition Field Name
- CVE-2026-83627 — Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log