Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-85889: Azure AI Foundry lets attackers gain higher access
CVE-2026-85889 · published 11 days ago
Summary
Azure AI Foundry does not check who is using a key function, so someone on the network who should not have permission can raise their rights to act like an administrator. This could let an attacker take control of services or data within the platform. Apply the latest security update from Microsoft or restrict network access to trusted users immediately.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | azure ai foundry | - |
| microsoft | azure_ai_foundry |
All versions
cpe:2.3:a:microsoft:azure_ai_foundry:-:*:*:*:*:*:*:* |
Original advisory text
Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889 vendor-advisory patch
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published17 Sep 2026
Updated27 Sep 2026
First seen17 Sep 2026
Track software like this
Free during beta