H3-2026-0023¶
Azure Container Registry Admin User Enabled
| Category | SECURITY_MISCONFIGURATION |
| Base Score | 6.5 |
Description¶
Where an Azure Container Registry has the built-in admin account enabled, this provides a static username and password for registry access.
Impact¶
Attackers who obtain the admin credentials can push malicious container images, pull sensitive images containing secrets, or modify existing images to inject backdoors into the software supply chain.