Executive brief
Azure Red Hat OpenShift (ARO) is a managed service that provides enterprise-grade Kubernetes clusters. A security flaw in the service's authorization logic could allow an attacker with existing high-level permissions to further escalate their privileges. This could lead to full control over the cloud environment, potentially resulting in data theft, service disruption, or unauthorized access to sensitive workloads.
Technical details
A vulnerability classified as improper authorization (CWE-285) exists within Azure Red Hat OpenShift (ARO). The flaw allows a network-based attacker who already possesses high privileges (PR:H) to bypass intended access controls and escalate their authority within the cluster or associated cloud environment. Due to the 'Changed' scope (S:C) in the CVSS metric, the exploit impact extends beyond the ARO component itself to other parts of the Azure infrastructure. Microsoft has identified this as a critical issue, though specific technical root causes or patch version numbers are not detailed in the initial disclosure.
Affected products
- Microsoft Azure Red Hat OpenShift (ARO) All versions
Timeline
- 2026-07-24: disclosed: Initial publication of CVE-2026-56160 by Microsoft and NVD.