rootpwn

critical · CVSS v3 10

CVE-2026-69865

CVE-2026-69865 is a critical authorization bypass in Microsoft Container Registry caused by a user-controlled key. It can allow an unauthori

Overview

CVE-2026-69865 is a critical authorization bypass in Microsoft Container Registry caused by a user-controlled key. It can allow an unauthorized network attacker to elevate privileges and access registry functions. It matters because container registries are central to software supply chains and deployment pipelines.

Description

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

Impact

The flaw can compromise confidentiality, integrity, and availability of registry data and image artifacts. Attackers may gain elevated access to pull, push, or manage container images if the vulnerable component is reachable. Organizations using the registry for production deployments, CI/CD pipelines, or multi-tenant environments are most exposed.

Affected products

  • Microsoft Container Registry

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
10
CVSS v4
EPSS

← All CVEs