CVE-2026-35435
8.6Microsoft · Azure AI Foundry
Improper access control in Azure AI Foundry M365 published agents allows unauthenticated network attackers to elevate privileges.
Executive summary
An improper access control vulnerability in Microsoft Azure AI Foundry allows unauthenticated attackers to elevate privileges over the network, presenting a significant risk to organizational environments.
Vulnerability
This flaw involves improper access control categorized under CWE-284, enabling unauthenticated remote attackers to execute privilege escalation attacks over network vectors without requiring user interaction.
Business impact
A successful exploitation of this vulnerability could lead to unauthorized privilege escalation, granting malicious actors elevated access within the affected M365 published agent environment. With a high CVSS score of 8.6, this issue threatens confidentiality and access controls, potentially exposing sensitive enterprise data and undermining cloud governance.
Remediation
Immediate Action: Apply the official security updates provided by Microsoft in the MSRC advisory as soon as possible.
Proactive Monitoring: Monitor Azure network traffic and authentication logs for anomalous privilege elevation patterns and unauthorized agent interactions.
Compensating Controls: Implement strict network segmentation and perimeter defenses to limit unauthorized external access to published AI foundry endpoints.
Exploitation status
Public Exploit Available: exploit_available (false / unknown)
Analyst recommendation
Given the high CVSS severity score of 8.6 and the potential for unauthenticated privilege escalation, security teams must treat this advisory with high urgency. Administrators should monitor Microsoft security channels for patch availability and apply remediation measures immediately to secure cloud AI assets against potential abuse.
More Microsoft CVEs
Sources
- Azure AI Foundry Elevation of Privilege Vulnerability Vendor advisory