CVE-2026-85889
Microsoft · Azure AI Foundry
A missing authentication vulnerability in Microsoft Azure AI Foundry allows unauthenticated attackers to perform privilege escalation over a network.
Executive summary
A critical authentication bypass vulnerability in Microsoft Azure AI Foundry permits unauthenticated network-based privilege escalation, posing a severe risk to cloud infrastructure integrity.
Vulnerability
This flaw stems from a missing authentication check for a critical function, as defined by CWE-306. It allows an unauthenticated remote attacker to gain elevated privileges within the Azure AI Foundry environment.
Business impact
The potential for unauthenticated privilege escalation represents a critical security failure that could lead to full system compromise, unauthorized data access, and total loss of confidentiality, integrity, and availability. With a CVSS score of 10.0, this vulnerability is categorized as critical, necessitating immediate attention to prevent unauthorized administrative control over sensitive AI workloads.
Remediation
Immediate Action: Review the Microsoft Security Response Center update guide for this CVE to identify available patches or mitigation steps provided by the vendor.
Proactive Monitoring: Monitor network traffic and access logs for unusual administrative activity or unauthorized attempts to access AI Foundry management endpoints.
Compensating Controls: Ensure that Azure service access is restricted to known, trusted IP ranges via Network Security Groups or Azure Firewall to limit the exposure of the management surface.
Exploitation status
Public Exploit Available: Unknown (exploit_available: false)
Analyst recommendation
Given the critical severity and the nature of the vulnerability, administrators must prioritize this issue. Consult the official Microsoft security advisory immediately to apply relevant security updates or configuration changes, and restrict network access to the affected service until a permanent fix is verified and deployed.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Held for re-check analysis graded thin
- Analyst report written
Sources
- Azure AI Foundry Elevation of Privilege Vulnerability Vendor advisory