Skip to content

H3-2026-0023

Azure Container Registry Admin User Enabled

Category SECURITY_MISCONFIGURATION
Base Score 6.5

Description

Where an Azure Container Registry has the built-in admin account enabled, this provides a static username and password for registry access.

Impact

Attackers who obtain the admin credentials can push malicious container images, pull sensitive images containing secrets, or modify existing images to inject backdoors into the software supply chain.

References