CVE-2026-68791
Microsoft · Azure Machine Learning
Incorrect authorization in Microsoft Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
Executive summary
An authorization flaw in Microsoft Azure Machine Learning permits unauthorized attackers to access confidential information over the network.
Vulnerability
The vulnerability is an incorrect authorization flaw (CWE-863) that allows an unauthenticated attacker to disclose sensitive information. The flaw permits access to data transmitted over the network that should be restricted by authorization policies.
Business impact
With a CVSS score of 8.6, this vulnerability poses a high risk to data confidentiality. Unauthorized disclosure of machine learning models, training data, or associated metadata could result in significant intellectual property theft or exposure of sensitive business information.
Remediation
Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68791 and apply all recommended security updates or configuration changes.
Proactive Monitoring: Review Azure activity logs for unauthorized access attempts or unusual data retrieval patterns originating from outside the expected environment.
Compensating Controls: Utilize Azure native security tools, such as Azure Policy and network security groups, to restrict access to the machine learning workspace and minimize the exposed attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Azure Machine Learning should treat this vulnerability with high priority. Users are strongly advised to monitor the official Microsoft advisory to identify the specific versions requiring updates and to apply those patches as soon as they are made available by the vendor.
More Microsoft CVEs all →
History
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
- Analyst report updated
Sources
- Azure Machine Learning Information Disclosure Vulnerability Vendor advisory