🔴 Critical  |  Source: Microsoft Security Response Center


A vulnerability in Microsoft Azure Kubernetes Service (AKS) allows an unauthenticated attacker to gain elevated privileges over a network by exploiting a missing authentication check on a critical function. This means an attacker without any valid credentials could potentially gain elevated control over Kubernetes workloads or the underlying cluster infrastructure. The network-based attack vector makes this particularly dangerous as it does not require local access to exploit.

Security Architect’s Take: Review your AKS cluster exposure immediately — ensure API servers and management endpoints are not publicly accessible and are protected by network policies or private cluster configurations. Monitor Microsoft’s patch guidance and apply any available updates or mitigations to affected AKS versions as a priority.

Original advisory: CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability