CVE-2026-69865: Microsoft Container Registry Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft Container Registry Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Microsoft Container Registry
Microsoft Azure Container Registry
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this vulnerability?
An unauthorized attacker can exploit it remotely over a network. No privileges or user interaction are required.
2
What is the security impact?
Successful exploitation allows elevation of privilege and can affect confidentiality and integrity at a high impact level. Availability impact is listed as none.
3
Which products should be assessed?
Assess deployments of Microsoft Container Registry and Microsoft Azure Container Registry.