Junglewise Threat Intelligence

CVE-2026-32193: Microsoft Azure Kubernetes Service path traversal code execution

CVE-2026-32193 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: Microsoft Azure Kubernetes Service. Vendors: Microsoft.

Executive brief

Microsoft Azure Kubernetes Service (AKS) is a managed platform used to deploy and manage containerized applications. A security vulnerability in this service allows an authorized user to bypass directory restrictions and execute unauthorized code on the underlying system. This could lead to a complete compromise of the affected environment, potentially allowing an attacker to access sensitive data or disrupt operations.

Technical details

A path traversal vulnerability (CWE-22) exists in Microsoft Azure Kubernetes Service (AKS). The flaw stems from improper limitation of a pathname to a restricted directory, which can be exploited by an authorized attacker with local access. By providing specially crafted path inputs, an attacker can escape the intended directory structure to execute arbitrary code. The vulnerability has a CVSS score of 8.8, notably featuring a 'Changed' Scope (S:C), indicating that an exploit can impact resources beyond the immediate security scope of the AKS component. Users should refer to the Microsoft Security Response Center (MSRC) for specific patching or mitigation guidance.

Affected products

  • Microsoft Azure Kubernetes Service (AKS)

Timeline

  • 2026-06-09: advisory: Initial publication by Microsoft and NVD.

References

Related threats