Database/Container, Kubernetes & orchestration
AKS Confidential Containers: elevation of privilege across the confidential container boundary
Impact
Microsoft describes this only as an elevation of privilege in Azure Kubernetes Service Confidential Containers, scored 9.0 with a changed scope, meaning the flaw lets an attacker gain privileges beyond the component that is broken. The affected product list covers AKS and the confcom tooling used to generate confidential container security policies. For an operator running confidential workloads on AKS - the pattern used when tenant data must stay opaque to the platform - the guarantee being weakened is the one the deployment exists for. The NVD record carries no technical detail beyond the MSRC title, so the exact path is not established here; read the MSRC entry before drawing conclusions about your configuration.
Who can reach it
Network-reachable with no privileges and no user interaction per the CVSS vector, at high attack complexity. The record does not describe what the attacker must reach, so treat the attack path as unestablished.
What to do
Microsoft fixed this service-side and in the tooling; follow the MSRC guidance for CVE-2024-21400, which includes updating the az confcom extension and rotating affected confidential container security policies. Because AKS is a managed control plane, most of the fix is not yours to schedule - the operator action is updating tooling and regenerating policies, not draining nodes.
References
Related entries
- Argo CD: Improper URL protocol filtering in link annotations enables client-side attacks against adminsCVE-2024-28175 · Argo CDCritical
- Argo CD: An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poisonCVE-2024-31989 · Argo CDCritical
- RHACM app-subscription: namespace edit rights escalate to cluster-admin via attacker-hosted Helm chartCVE-2026-10090 · Red Hat Advanced Cluster Management - multicluster-operators-subscription (app-subscription controller)Critical
- OpenChoreo cluster gateway: unauthenticated internal listener exposes cross-tenant secrets and pod execCVE-2026-73842 · OpenChoreo cluster gateway (internal /api/proxy, /api/exec, /api/wirelogs listener)Critical
- Argo Workflows (controller, podSpecPatch in Strict/Secure template reference mode): A podSpecPatch on the submittedCVE-2026-31892 · Argo Workflows (controller, podSpecPatch in Strict/Secure template reference mode)High
- Argo Workflows (controller, ArtifactGC.PodSpecPatch / template reference allow-list): The allow-list that is supposedCVE-2026-54526 · Argo Workflows (controller, ArtifactGC.PodSpecPatch / template reference allow-list)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.