CVE-2026-68791

Microsoft · Azure Machine Learning

Incorrect authorization in Microsoft Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Executive summary

An authorization flaw in Microsoft Azure Machine Learning permits unauthorized attackers to access confidential information over the network.

Vulnerability

The vulnerability is an incorrect authorization flaw (CWE-863) that allows an unauthenticated attacker to disclose sensitive information. The flaw permits access to data transmitted over the network that should be restricted by authorization policies.

Business impact

With a CVSS score of 8.6, this vulnerability poses a high risk to data confidentiality. Unauthorized disclosure of machine learning models, training data, or associated metadata could result in significant intellectual property theft or exposure of sensitive business information.

Remediation

Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68791 and apply all recommended security updates or configuration changes.

Proactive Monitoring: Review Azure activity logs for unauthorized access attempts or unusual data retrieval patterns originating from outside the expected environment.

Compensating Controls: Utilize Azure native security tools, such as Azure Policy and network security groups, to restrict access to the machine learning workspace and minimize the exposed attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Azure Machine Learning should treat this vulnerability with high priority. Users are strongly advised to monitor the official Microsoft advisory to identify the specific versions requiring updates and to apply those patches as soon as they are made available by the vendor.

More Microsoft CVEs all →

History

  1. Collected by CVE Brief via github
  2. Held for re-check analysis graded thin
  3. Analyst report written
  4. Analyst report updated

Sources