CVE-2026-85889

Microsoft · Azure AI Foundry

A missing authentication vulnerability in Microsoft Azure AI Foundry allows unauthenticated attackers to perform privilege escalation over a network.

Executive summary

A critical authentication bypass vulnerability in Microsoft Azure AI Foundry permits unauthenticated network-based privilege escalation, posing a severe risk to cloud infrastructure integrity.

Vulnerability

This flaw stems from a missing authentication check for a critical function, as defined by CWE-306. It allows an unauthenticated remote attacker to gain elevated privileges within the Azure AI Foundry environment.

Business impact

The potential for unauthenticated privilege escalation represents a critical security failure that could lead to full system compromise, unauthorized data access, and total loss of confidentiality, integrity, and availability. With a CVSS score of 10.0, this vulnerability is categorized as critical, necessitating immediate attention to prevent unauthorized administrative control over sensitive AI workloads.

Remediation

Immediate Action: Review the Microsoft Security Response Center update guide for this CVE to identify available patches or mitigation steps provided by the vendor.

Proactive Monitoring: Monitor network traffic and access logs for unusual administrative activity or unauthorized attempts to access AI Foundry management endpoints.

Compensating Controls: Ensure that Azure service access is restricted to known, trusted IP ranges via Network Security Groups or Azure Firewall to limit the exposure of the management surface.

Exploitation status

Public Exploit Available: Unknown (exploit_available: false)

Analyst recommendation

Given the critical severity and the nature of the vulnerability, administrators must prioritize this issue. Consult the official Microsoft security advisory immediately to apply relevant security updates or configuration changes, and restrict network access to the affected service until a permanent fix is verified and deployed.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Held for re-check analysis graded thin
  4. Analyst report written

Sources