CVE-2026-69865
Microsoft · Azure Container Registry
An authorization bypass in Microsoft Azure Container Registry allows unauthenticated attackers to elevate privileges via a user-controlled key.
Executive summary
A critical authorization bypass vulnerability in Microsoft Azure Container Registry allows unauthenticated attackers to elevate privileges over a network.
Vulnerability
The vulnerability involves an authorization bypass through a user-controlled key (CWE-639), which permits an unauthenticated attacker to bypass security checks. This allows for unauthorized privilege escalation across the network, effectively subverting the registry's access controls.
Business impact
The CVSS score of 10.0 reflects the critical nature of this flaw, as it allows attackers to gain unauthorized elevated access to container images and registry configurations. This could lead to the injection of malicious code into containerized applications, resulting in supply chain compromise and widespread data breaches.
Remediation
Immediate Action: Review the Microsoft Security Response Center advisory for CVE-2026-69865 and apply the mandatory security updates to the Azure Container Registry environment.
Proactive Monitoring: Audit access logs for the Container Registry to identify unusual user activity or unauthorized elevation requests associated with registry keys.
Compensating Controls: Utilize Azure role-based access control (RBAC) to limit the exposure of registry keys and ensure that only necessary services have access to sensitive container resources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations relying on Azure Container Registry must treat this vulnerability with extreme urgency. Apply the vendor-provided patches immediately upon availability and audit all current registry keys to ensure no unauthorized or excessive permissions are currently in place.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
- Analyst report updated