Insecure Direct Object Reference in Microsoft Container Migration Solution Accelerator
CVE-2026-73298

8.7HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73298?

The Microsoft Container Migration Solution Accelerator, a multi-service application designed for migrating container configurations to Azure Kubernetes Service, has a security issue that allows authenticated users to perform unauthorized operations. Specifically, the vulnerability arises from missing ownership checks in various API endpoints, enabling users to read, write, and delete processes and files belonging to other authenticated individuals within the organization. This flaw exists in both the process and file management APIs, relying on Entra ID for authentication but lacking the necessary authorization mechanisms, potentially leading to data breaches and unauthorized modifications.

Affected Version(s)

Container-Migration-Solution-Accelerator <= 2.1.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.