• PATCH AVAILABLE

CVE-2026-69865: pre-auth authorization bypass in Microsoft Azure Container Registry

An attacker can bypass authorization in Microsoft Azure Container Registry and gain privileged access to registry resources, potentially allowing full read and write control; this issue is tracked as CVE-2026-69865. The vulnerability affects Azure Container Registry (affected versions/details unspecified in the advisory). According to published metrics the flaw requires only network access and no prior authentication or user interaction to exploit, enabling remote abuse from network-exposed environments.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00815
CWE
CWE-639
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a remote, pre-auth vulnerability with maximum severity (CVSS 10.0) so prioritize mitigation now; immediately limit registry exposure and prepare to apply vendor fixes when they are released.

What is CVE-2026-69865?

An attacker can bypass authorization in Microsoft Azure Container Registry and gain privileged access to registry resources, potentially allowing full read and write control; this issue is tracked as CVE-2026-69865. The vulnerability affects Azure Container Registry (affected versions/details unspecified in the advisory). According to published metrics the flaw requires only network access and no prior authentication or user interaction to exploit, enabling remote abuse from network-exposed environments. The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Azure Container Registry are affected?

BRANCHAFFECTEDFIXED
Azure Container Registry-

Is CVE-2026-69865 being exploited?

There are no public reports of active exploitation as of 2026-09-29.

How to fix CVE-2026-69865

  1. Follow Microsoft guidance and apply vendor updates as soon as fixed builds are released for Azure Container Registry.
  2. Restrict public access to registries and limit network exposure using firewalls and private endpoints.
  3. Rotate keys and credentials associated with affected registries and remove any untrusted user-controlled keys.
  4. Monitor registry access logs and alert on anomalous pushes, pulls, or permission changes.

Frequently asked questions

Is CVE-2026-69865 being actively exploited?

There are no public reports of exploitation of CVE-2026-69865 as of 2026-09-29.

Which Azure Container Registry versions are affected by CVE-2026-69865?

The advisory identifies Azure Container Registry as affected but does not list specific version or build numbers.

Is there a patch for CVE-2026-69865?

A patch is reported as available in the advisory metadata, but no fixed version identifiers were provided; apply Microsoft updates as they publish fixed releases.

Does CVE-2026-69865 require authentication?

No — the vulnerability can be exploited without prior authentication according to the published vulnerability metrics.

References