• PATCH AVAILABLE

CVE-2026-56163: pre-auth privilege escalation in Microsoft Azure Kubernetes Service

An unauthenticated attacker can elevate privileges on Microsoft Azure Kubernetes Service, allowing full confidentiality, integrity and availability impact. CVE-2026-56163 is a missing-authentication vulnerability (CWE-306) that affects the Azure Kubernetes Service branch; vendor advisories list the service as affected but do not name fixed releases in the provided data. An attacker only needs network access to the service endpoint and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00901
CWE
CWE-306
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the issue grants unauthenticated full system impact and carries a CVSS 10.0 base score, so immediately follow vendor guidance and limit network exposure to the service.

What is CVE-2026-56163?

An unauthenticated attacker can elevate privileges on Microsoft Azure Kubernetes Service, allowing full confidentiality, integrity and availability impact. CVE-2026-56163 is a missing-authentication vulnerability (CWE-306) that affects the Azure Kubernetes Service branch; vendor advisories list the service as affected but do not name fixed releases in the provided data. An attacker only needs network access to the service endpoint and does not require valid credentials or user interaction. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Microsoft Azure Kubernetes Service are affected?

BRANCHAFFECTEDFIXED
Azure Kubernetes Service-

Is CVE-2026-56163 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-56163

  1. Apply the vendor's patch or advisory for Azure Kubernetes Service as soon as it is available.
  2. If a patch cannot be applied immediately, restrict network access to AKS control and management endpoints to trusted networks only.
  3. Require and enforce authentication and authorization controls where possible, and disable any insecure management interfaces.
  4. Monitor AKS audit logs and network traffic for suspicious privilege-escalation activity and signs of compromise.

Frequently asked questions

Is CVE-2026-56163 being actively exploited?

There are no public reports of active exploitation of CVE-2026-56163 as of 2026-09-29.

Which Azure Kubernetes Service versions are affected by CVE-2026-56163?

The vulnerability affects the Azure Kubernetes Service branch; vendor information supplied here does not list specific fixed versions.

Is there a patch for CVE-2026-56163?

Vendor data indicates a patch is available; follow Microsoft’s Azure Kubernetes Service guidance and apply updates as directed.

Does CVE-2026-56163 require authentication?

No, the flaw is a missing-authentication issue in Azure Kubernetes Service and allows unauthenticated access to a critical function.

References