Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-69865 2026-09-17

CVE-2026-69865: Maximum-Severity Authorization Bypass in Azure Container Registry

"Microsoft disclosed a CVSS 10.0 authorization bypass in Azure Container Registry that lets an unauthenticated attacker elevate privileges over the network."

Microsoft disclosed a CVSS 10.0 authorization bypass in Azure Container Registry that lets an unauthenticated attacker elevate privileges over the network.

What Is It

CVE-2026-69865 is an authorization bypass through a user-controlled key (CWE-639) in Microsoft Container Registry. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network." The CVE was published 2026-09-17 and is currently in "Received" status in NVD, meaning analysis is still pending.

Microsoft assigned a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. Every exploitability factor is at its worst setting: network-reachable, low attack complexity, no privileges required, no user interaction. The scope is Changed, and both confidentiality and integrity impact are rated High. Availability impact is None.

Why It Matters

A perfect 10.0 is rare, and the vector explains why it lands here: the exploitability subscore is the maximum 3.9, and the changed scope means a successful attack reaches resources beyond the initially vulnerable component. With High confidentiality and integrity impact against a container registry, the exposure model is an attacker who can both read and alter registry contents without credentials.

The CVE carries Microsoft's exclusively-hosted-service tag. That designation means the issue lives in the cloud service itself rather than in software customers run.

What's Vulnerable

Microsoft lists the affected product as Azure Container Registry, vendor Microsoft, with version recorded as - (affected). No CPE entries are present in the NVD record, and no specific version boundaries are supplied. The description refers to the component as Microsoft Container Registry.

Patch Status

No patch, version number, or customer remediation step is present in the supplied data. The exclusively-hosted-service tag indicates the fix is applied service-side by Microsoft. There is no CISA KEV entry for this CVE in the supplied material, so there is no confirmation of active exploitation and no KEV-mandated due date or required action. Administrators should consult the MSRC advisory below for Microsoft's current guidance.

Sources