CVSS 9.9 Flaw in Azure SRE Agent Breaks OBO Flow, Extending Blast Radius Beyond the Agent
Microsoft has disclosed CVE-2026-62830, a critical elevation of privilege vulnerability in the Azure SRE Agent. With a CVSS 3.1 base score of 9.9, the flaw is defined by a Scope Changed (S:C) vector — the mechanic that drives the severity, because it lets an attacker bypass the agent’s security boundary and reach resources across the…