PT-2026-29906 · Microsoft · Azure Kubernetes Service

Amir Gombo

·

Published

2026-04-02

·

Updated

2026-04-10

·

CVE-2026-33105

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Azure Kubernetes Service (affected versions not specified)
Description Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. The flaw allows unauthenticated attackers to escalate privileges remotely. The scope of the issue allows attackers to potentially affect resources beyond their initial access, possibly crossing tenant boundaries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33105

Affected Products

Azure Kubernetes Service