AKS Path Traversal CVE-2026-32193 Can Escalate to Microsoft Copilot Hijack
A vulnerability tracked as CVE-2026-32193, rated 8.8 CVSS, affects Azure Kubernetes Service's file path handling, allowing attackers to escape a restricted directory via uncanonicalised path sequences. Discovered amid a record 206-vulnerability Patch Tuesday in June 2026, the flaw was widely underreported due to its low EPSS score and misleading automated writeups. Exploiting the bug grants root access on a managed AKS node, exposing kubelet credentials, service account tokens, and cloud identity material. Researchers warn this node-level compromise can extend to Microsoft Copilot if the assistant's identity holds broad API permissions reachable from the hijacked node. Microsoft has issued a fix in AKS node image build v0.20260213.5, and administrators are advised to upgrade all node pools and audit federated service account permissions immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in