CyberICT

CVE-2026-33105

Microsoft · Published April 2, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability. Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • Azure Kubernetes Service

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C