PT-2026-42844 · Microsoft · Azure Orbital Spatio

Michal Kamensky

·

Published

2026-05-21

·

Updated

2026-05-27

·

CVE-2026-40412

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Orbital Spatio (affected versions not specified)
Description Unrestricted upload of files with dangerous types allows an unauthorized attacker to execute code over a network. This issue enables unauthenticated Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a target machine from a remote location.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2026-07698
CVE-2026-40412

Affected Products

Azure Orbital Spatio