« Back to list

Microsoft

Microsoft Azure Hdinsight: vulnerabilities and CVEs

Microsoft Azure Hdinsight has 10 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs10
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-81349High (7.2)1.0%—Sep 8, 2026
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
CVE-2026-21529Medium (5.4)0.66%—Feb 10, 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
CVE-2023-36419Critical (9.8)1.7%—Oct 10, 2023
Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
CVE-2023-38156High (7.2)2.0%—Sep 12, 2023
Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
CVE-2023-38188Medium (4.5)1.0%—Aug 8, 2023
Azure Apache Hadoop Spoofing Vulnerability
CVE-2023-36881Medium (4.5)1.0%—Aug 8, 2023
Azure Apache Ambari Spoofing Vulnerability
CVE-2023-36877Medium (4.5)1.0%—Aug 8, 2023
Azure Apache Oozie Spoofing Vulnerability
CVE-2023-35394Medium (4.6)0.97%—Aug 8, 2023
Azure HDInsight Jupyter Notebook Spoofing Vulnerability
CVE-2023-35393Medium (4.5)1.4%—Aug 8, 2023
Azure Apache Hive Spoofing Vulnerability
CVE-2023-23408Medium (4.5)4.0%—Mar 14, 2023
Azure Apache Ambari Spoofing Vulnerability

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft