CVE-2026-32193: Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
Other sources
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v0.20260213.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32193?
The severity of CVE-2026-32193 is high, with a score of 8.8.
What type of vulnerability is described by CVE-2026-32193?
CVE-2026-32193 is a path traversal vulnerability that allows remote code execution.
How can CVE-2026-32193 be exploited?
CVE-2026-32193 can be exploited by an authorized attacker to execute code locally through improper pathname limitations.
What software is affected by CVE-2026-32193?
CVE-2026-32193 affects Microsoft Azure Kubernetes Service (AKS).
How do I fix CVE-2026-32193?
To fix CVE-2026-32193, it is recommended to apply the latest updates provided by Microsoft for Azure Kubernetes Service.