Microsoft has published information about CVE-2026-56163, a security vulnerability affecting Azure Kubernetes Service, also known as AKS. The issue was caused by missing authentication for a critical function of the service.
An unauthorized attacker could potentially have exploited the vulnerability over a network to elevate privileges within the affected service.
Technical classification
Product: Microsoft Azure Kubernetes Service
Impact: Elevation of privilege
Weakness: CWE-306 – Missing Authentication for Critical Function
CVSS base score: 10.0
CVSS temporal score: 8.7
Attack vector: Network
User interaction required: None
Privileges required: None
Publicly disclosed: No
Exploitation detected: No
Current status
Microsoft has already fully mitigated the vulnerability within the affected cloud service. Customers do not need to download an update or make configuration changes.
According to Microsoft, the CVE was published to provide additional transparency regarding security vulnerabilities in Microsoft-operated cloud services.
Recommended action
No immediate customer action is required for Azure Kubernetes Service users. Administrators should document the notice and continue following their normal Azure security and monitoring procedures.
