Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-85889: Azure AI Foundry lets attackers gain higher access

CVE-2026-85889 · published 11 days ago
Summary

Azure AI Foundry does not check who is using a key function, so someone on the network who should not have permission can raise their rights to act like an administrator. This could let an attacker take control of services or data within the platform. Apply the latest security update from Microsoft or restrict network access to trusted users immediately.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft azure ai foundry -
microsoft azure_ai_foundry All versions
cpe:2.3:a:microsoft:azure_ai_foundry:-:*:*:*:*:*:*:*
Original advisory text
Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published17 Sep 2026
Updated27 Sep 2026
First seen17 Sep 2026
Sources
CVE-2026-85889 · MITRE
Track software like this
Free during beta