CVE-2026-23655: Microsoft ACI Confidential Containers Information Disclosure Vulnerability
Overview
- Severity
- Medium (CVSS 6.5)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- Category
- Information Disclosure
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Feb
- Released
- 2026-02-10
- EPSS Score
- 0.08% (percentile: 24.8%)
Description
Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
FAQ
What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is secret tokens and keys.
Affected Products (1)
Azure
- Microsoft ACI Confidential Containers
Security Updates (2)
Acknowledgments
Microsoft Offensive Research and Security Engineering with Microsoft, Microsoft Offensive Research and Security Engineering with Microsoft
Revision History
- 2026-02-10: Information published.