CVE-2026-23651
Microsoft Aci Confidential Containers
Raw vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2026-23651 is a medium-severity Permissive Regular Expression (CWE-625) vulnerability in Microsoft Aci Confidential Containers. Its CVSS base score is 6.7 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 45th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-9886
Vulnerability Data
Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
SI-10 requires validity checks on inputs, directly stopping permissive regex patterns from being used for validation.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require robust input-validation regex and testing that would prevent permissive patterns.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect permissive regex through fuzzing or negative test cases.
Secure development lifecycle requires validation of input mechanisms, including regex, reducing permissive patterns.
Application security requirements mandate strict input validation rules that would catch overly permissive regex.
Secure coding standards directly prohibit permissive regex and enforce strict pattern validation.