Executive brief
Microsoft Azure Kubernetes Service (AKS) is a managed platform used by organizations to deploy and manage containerized applications. A critical security flaw has been identified that allows an unauthenticated attacker to gain full administrative control over the Kubernetes environment. This could lead to the theft of sensitive data, complete service disruption, and the ability for attackers to move laterally through the organization's cloud infrastructure.
Technical details
A vulnerability classified as CWE-306 (Missing Authentication for Critical Function) exists within Microsoft Azure Kubernetes Service (AKS). The flaw allows a remote, unauthenticated attacker to access critical functions over the network without providing valid credentials. Due to the 'Changed' scope in the CVSS metric, an exploit allows the attacker to elevate privileges beyond the AKS environment to impact other components of the cloud infrastructure. This vulnerability has been assigned a CVSS score of 10.0, indicating maximum impact on confidentiality, integrity, and availability. Users should refer to the Microsoft Security Update Guide for specific mitigation or patching instructions for their hosted environments.
Affected products
- Microsoft Azure Kubernetes Service (AKS) All versions
Timeline
- 2026-07-24: disclosed: Initial publication of CVE-2026-56163 by Microsoft.
- 2026-07-24: advisory: NVD record published.