---
schema: 1
kind: vulnerability
title: "CVE-2026-42822 — Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, \"Exploitation More Likely\""
headline: "CVE-2026-42822 — Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, \"Exploitation More Likely\""
summary: "Microsoft ships CVE-2026-42822 — CVSS 10.0 unauthenticated network EoP in Azure Local Disconnected Operations (ALDO) with MSRC exploitability assessment \"Exploitation More Likely\"; only manually-operated air-gapped Azure Local stacks need action (cloud-managed Azure already protected) (Microsoft MSRC, 2026-05-18)."
discovered_at: "2026-05-21T05:00:03Z"
event_date: 2026-05-18
run_id: 2026-05-21-77cdc4cd
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - cloud
  - auth-bypass
  - priv-esc
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-42822
    cvss: "10.0"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42822"
    publisher: Microsoft MSRC
    role: primary
closed_sources: []
evidence: []
verification: single-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Upgrade Azure Local Disconnected Operations (ALDO) to v2604+** on every air-gapped / data-sovereignty Azure Local deployment. The CVE-2026-42822 unauth EoP is rated CVSS 10.0 and \"Exploitation More Likely\" — cloud-managed Azure is already protected, manual stacks are not (. Restrict the ALDO management plane to admin-only OOB subnets until the upgrade is complete."
migrated_from: briefs/2026-05-21.md
---

Microsoft assigned CVE-2026-42822 (CVSS 3.1 = 10.0, CWE-287 Improper Authentication, vector `AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H`) to an authentication-bypass flaw in Azure Local Disconnected Operations (ALDO) — Microsoft's solution for running Azure services in air-gapped or partially-disconnected infrastructure environments — that allows an unauthorised network attacker to elevate privileges over a network with no credentials and no prior foothold ([Microsoft MSRC, 2026-05-18](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42822)). MSRC rates "Exploitation More Likely"; no in-the-wild exploitation observed and no public PoC at advisory release. Cloud-managed Azure customers using Microsoft-operated Resource Manager environments are already protected — only manually-operated air-gapped Azure Local stacks need action. Remediation requires upgrading ALDO to version 2604 or later via the standard ALDO update channel. **Defender takeaway:** EU public-sector operators running Azure Local for data-sovereignty / federal data-residency compliance (a common pattern in Bundesverwaltung and German Bundesbehörden environments) should treat this as a Patch-Tuesday-class emergency on disconnected infrastructure where update cadence is typically slower than cloud-managed Azure. Restrict the ALDO management plane to admin-only OOB subnets until v2604 is installed.
