Path Traversal Vulnerability in Microsoft Azure Kubernetes Service
CVE-2026-32193

8.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 June 2026

What is CVE-2026-32193?

A vulnerability within Microsoft Azure Kubernetes Service (AKS) allows an authorized attacker to bypass access controls through improper limitation of a pathname, leading to potential local code execution. This flaw can be exploited by sending crafted requests that manipulate the directory traversal mechanism, compromising the integrity and security of the service. It’s critical for organizations utilizing AKS to apply the appropriate patches to mitigate the risk of this vulnerability.

Affected Version(s)

Azure Kubernetes Service 1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.