Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-69865: Azure Container Registry lets attackers gain higher rights

CVE-2026-69865 · published 11 days ago
Summary

The Azure Container Registry service can be tricked into granting more access than intended. An attacker who can send specially crafted requests could increase their privileges and move around the network. Apply the latest updates from Microsoft and review access controls to protect against this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft azure container registry -
Original advisory text
Microsoft Container Registry Elevation of Privilege Vulnerability
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published17 Sep 2026
Updated27 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-69865 · MITRE
Track software like this
Free during beta