Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-56163Privilege escalation in Azure Kubernetes Service

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

View on NVD

Analysis

Microsoft Azure Kubernetes Service presenta una falta de autenticación que permite a un atacante remoto elevar sus privilegios en el clúster sin autorización previa. Este fallo compromete la seguridad de la infraestructura de contenedores y permite el control administrativo de los recursos afectados a través de la red.

Relevant roles

KubernetesCloudDockerCyberSecurityBackend

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-306

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Published: 7/24/2026, 3:18:33 PM
Last modified: 7/24/2026, 8:48:18 PM

References

HomeEventsBlogResourcesCoursesTeam