CVE-2026-32207
8.8Microsoft · Azure Machine Learning
Improper neutralization of input in Azure Machine Learning allows unauthenticated attackers to perform cross-site scripting and spoofing over a network.
Executive summary
An unauthenticated cross-site scripting vulnerability in Microsoft Azure Machine Learning allows remote attackers to execute malicious scripts and perform spoofing attacks.
Vulnerability
This is a cross-site scripting flaw classified as CWE-79, caused by improper neutralization of input during web page generation, which can be triggered remotely by an unauthenticated attacker requiring user interaction.
Business impact
A successful exploit could allow malicious actors to execute arbitrary scripts in the context of a victim session, potentially leading to unauthorized access, session hijacking, or data compromise. The high CVSS score of 8.8 reflects the severity of potential impacts, including total technical impact on confidentiality, integrity, and availability if weaponized against administrative users.
Remediation
Immediate Action: Apply the security updates provided by Microsoft through the official update guide as soon as possible.
Proactive Monitoring: Monitor network traffic and application access logs for unusual patterns or suspicious requests targeting the Azure Machine Learning interface.
Compensating Controls: Deploy Web Application Rules to inspect and block suspicious payloads containing script tags or common cross-site scripting vectors.
Exploitation status
Public Exploit Available: exploit_available (false / unknown)
Analyst recommendation
Given the high CVSS score and the potential for severe system and data compromise, administrators should treat this vulnerability with urgency. Ensure that all applicable vendor patches are applied promptly to neutralize the threat vector.
More Microsoft CVEs
Sources
- Azure Machine Learning Notebook Spoofing Vulnerability Vendor advisory