critical · CVSS v3 10
CVE-2026-69865
CVE-2026-69865 is a critical authorization bypass in Microsoft Container Registry caused by a user-controlled key. It can allow an unauthori
Overview
CVE-2026-69865 is a critical authorization bypass in Microsoft Container Registry caused by a user-controlled key. It can allow an unauthorized network attacker to elevate privileges and access registry functions. It matters because container registries are central to software supply chains and deployment pipelines.
Description
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
Impact
The flaw can compromise confidentiality, integrity, and availability of registry data and image artifacts. Attackers may gain elevated access to pull, push, or manage container images if the vulnerable component is reachable. Organizations using the registry for production deployments, CI/CD pipelines, or multi-tenant environments are most exposed.
Affected products
- Microsoft Container Registry
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 10
- CVSS v4
- —
- EPSS
- —