Microsoft has disclosed a critical (CVSS 9.1) improper-authorization flaw in Azure Red Hat OpenShift (ARO) that lets an authorized attacker escalate privileges over a network.
What Is It
CVE-2026-56160 is an improper authorization vulnerability (CWE-285) in Azure Red Hat OpenShift (ARO), Microsoft's managed OpenShift service. According to Microsoft's advisory, the flaw "allows an authorized attacker to elevate privileges over a network." It carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H.
Why It Matters
The vulnerability is network-exploitable with low attack complexity and requires no user interaction. Its scope is marked as changed, meaning a successful attack can affect resources beyond the initially vulnerable component. Confidentiality, integrity, and availability impacts are all rated HIGH, a successful exploit could give an already-authorized attacker elevated control over the environment. The one mitigating factor is that exploitation requires high existing privileges (PR:H).
What's Vulnerable
- Vendor: Microsoft
- Product: Azure Red Hat OpenShift (ARO)
- Affected versions: Listed as "-" (unspecified) and marked affected.
Microsoft tags this CVE as an exclusively-hosted-service, indicating it applies to the managed cloud service rather than customer-installed software.
Patch Status
The supplied source material contains no CISA KEV entry for CVE-2026-56160, so there is no confirmation of active exploitation and no KEV-mandated remediation action in this data. Because ARO is an exclusively hosted service, remediation is typically handled by the provider; no specific patch, version, or required customer action is stated in the supplied NVD record. Refer to Microsoft's advisory for authoritative update guidance.
Sources
- Microsoft Security Response Center (MSRC), Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56160
- NVD, CVE-2026-56160 (record published 2026-07-24)