CVE-2026-33105 is a critical improper authorization vulnerability affecting Microsoft Azure Kubernetes Service (AKS). Rated with a CVSS score of 10.0, this flaw allows an unauthorized attacker to remotely elevate privileges with low attack complexity. Exploitation can lead to a complete compromise of confidentiality, integrity, and availability of the affected service. While there are no known active exploits or public exploit code available, the vulnerability has garnered some community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_kubernetes_service:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.