SUSE and openSUSE Azure Storage AzCopy Security Update Addresses Critical Vulnerabilities

SUSE and openSUSE Azure Storage AzCopy Security Update Addresses Critical Vulnerabilities

First seen 8 Aug 2026, 17:35 UTC Linuxsecurity 97% similarity 72.0

Article Content

Browse articles
ThreatCluster

An important security update for azure-storage-azcopy has been released, addressing two critical vulnerabilities: CVE-2026-39821 and CVE-2026-56852. CVE-2026-39821 allows for validation bypass and privilege escalation due to improper handling of Punycode-encoded labels, while CVE-2026-56852 can lead to an infinite loop from invalid UTF-8 input. Both vulnerabilities affect systems using the azcopy tool, with potential impacts on data integrity and system security. The update includes version 10.32.6, which also implements compliance with the FIPS 140-3 standard. Users are advised to apply the patches immediately to mitigate risks. The vulnerabilities were published on May 22 and July 21, 2026, respectively. The update is critical for maintaining the security of affected systems.

Key Points: • Two critical vulnerabilities (CVE-2026-39821, CVE-2026-56852) fixed in the update. • CVE-2026-39821 allows privilege escalation through validation bypass. • Immediate patching is recommended for all users of azure-storage-azcopy.

ThreatCluster AI How this analysis works

Timeline

2026-05-22
CVE-2026-39821 published
A vulnerability allowing validation bypass and privilege escalation was disclosed, affecting azcopy.
Linuxsecurity
2026-07-21
CVE-2026-56852 published
A vulnerability that can lead to an infinite loop from invalid UTF-8 input was disclosed.
Linuxsecurity
2026-08-07
Security update released
SUSE released version 10.32.6 for azure-storage-azcopy to address critical vulnerabilities.
Linuxsecurity

Community

Browse all →