Skip to content
CVSS 9.4 · CRITICAL

CVE-2026-50516Privilege Escalation in Azure Kubernetes Service (AKS)

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

View on NVD

Analysis

A critical authentication bypass has been identified in Azure Kubernetes Service (AKS). This vulnerability allows an unauthorized attacker to elevate privileges over a network, potentially leading to full cluster compromise for those using Microsoft's managed Kubernetes service.

Severity

Score: 9.4(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: LOW
Weakness (CWE): CWE-306

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Published: 8/11/2026, 5:18:02 PM
Last modified: 8/11/2026, 5:18:02 PM

References

HomeEventsBlogResourcesCoursesTeam