Insecure Direct Object Reference in Microsoft Container Migration Solution Accelerator
CVE-2026-73298
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 12 August 2026
What is CVE-2026-73298?
The Microsoft Container Migration Solution Accelerator, a multi-service application designed for migrating container configurations to Azure Kubernetes Service, has a security issue that allows authenticated users to perform unauthorized operations. Specifically, the vulnerability arises from missing ownership checks in various API endpoints, enabling users to read, write, and delete processes and files belonging to other authenticated individuals within the organization. This flaw exists in both the process and file management APIs, relying on Entra ID for authentication but lacking the necessary authorization mechanisms, potentially leading to data breaches and unauthorized modifications.
Affected Version(s)
Container-Migration-Solution-Accelerator <= 2.1.2