logo

Azure Kubernetes Bug Lays Open Cluster Secrets

ID: 5f436736-6739-5dfe-9afa-fb0cbbbb2e85

STIX ID: report--5f436736-6739-5dfe-9afa-fb0cbbbb2e85

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-08-20

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

Mandiant disclosed a critical AKS privilege-escalation vulnerability where an attacker with command execution in a pod could access an undocumented WireServer endpoint to retrieve TLS bootstrap tokens and generate kubelet certificates, enabling full cluster compromise; the flaw impacted AKS clusters using Azure CNI and Azure Network Policy, did not require root or hostNetwork, and Microsoft patched the issue—organizations are advised to audit AKS configurations, rotate Kubernetes secrets, enforce strict pod security and NetworkPolicies, and improve logging and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.