CVE-2026-21226

Aliases:GHSA-jm66-cg57-jjv5PYSEC-2026-1208
Analyzed
Published: 13 Jan 2026, 18:04
Last modified:01 Apr 2026, 13:49

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.78% LOW
1% probability -0.92%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Jan 2026, 18:04
Published
Vulnerability first disclosed
01 Apr 2026, 13:49
Last Modified
Vulnerability information updated

Description

Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.78% Percentile: 51%

Techniques & Countermeasures

  • CWE-502Deserialization of Untrusted Data

    The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Affected Systems

  • microsoftazure_core_shared_client_library

    ≥ 1.1.0, < 1.38.0

  • microsoftazure core shared client library for python

    ≥ 1.1.0, < 1.38.0

  • microsoftazure_sdk_for_python

    ≥ 1.1.0, ≤ 1.38.0

  • PyPIazure-core

    < 1.38.0

References (6)