CVE-2026-33105
Microsoft · Published April 2, 2026
10.0
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability. Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Affected Products
- Azure Kubernetes Service
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C