PT-2026-29906 · Microsoft · Azure Kubernetes Service
Amir Gombo
·
Published
2026-04-02
·
Updated
2026-04-10
·
CVE-2026-33105
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Azure Kubernetes Service (affected versions not specified)
Description
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. The flaw allows unauthenticated attackers to escalate privileges remotely. The scope of the issue allows attackers to potentially affect resources beyond their initial access, possibly crossing tenant boundaries.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azure Kubernetes Service