Executive brief
A critical security flaw has been identified in Microsoft Azure Kubernetes Service (AKS), a platform used to deploy and manage containerized applications. This vulnerability allows an unauthorized person to gain high-level administrative control over the system remotely. If exploited, an attacker could fully compromise the environment, potentially leading to the theft of sensitive data, disruption of services, or complete takeover of the cloud infrastructure.
Technical details
An improper authorization vulnerability (CWE-285/CWE-863) exists in Microsoft Azure Kubernetes Service (AKS). The flaw allows a remote, unauthenticated attacker to bypass security checks and elevate their privileges to a higher level within the Kubernetes environment. According to the CVSS 3.1 score of 10.0, the attack vector is network-based, requires low complexity, and involves no user interaction. Successful exploitation results in a total loss of confidentiality, integrity, and availability, with the impact extending beyond the immediate security scope of the AKS component. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes, but users should consult the MSRC update guide for specific configuration requirements.
Affected products
- Microsoft Azure Kubernetes Service All versions
Timeline
- 2026-04-02: disclosed
- 2026-04-03: advisory