Executive brief
Microsoft Container Registry is a cloud service for storing and managing container images used in application deployment. An authorization bypass vulnerability in how the service validates user-controlled cryptographic keys allows an attacker to escalate their privileges and gain unauthorized access to containerized applications and data across a network without requiring legitimate credentials.
Technical details
The vulnerability is an authorization bypass in Microsoft Container Registry caused by insufficient validation of user-controlled keys used in the authentication mechanism. The flaw allows an attacker on the network to bypass access controls and elevate privileges by manipulating authentication parameters. An attacker can exploit this remotely without prior authentication to the registry, potentially gaining full administrative control. The vulnerability enables privilege escalation and unauthorized access to container images and associated secrets. Patches are expected from Microsoft through their standard security update channels.
Affected products
- Microsoft Container Registry All versions
Timeline
- 2026-09-17: disclosed