CVE-2026-85889: Azure AI Foundry Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Azure AI Foundry Elevation of Privilege Vulnerability
Other sources
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Azure AI Foundry
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable over a network and requires no prior privileges or user interaction. The attack complexity is rated low.
2
What could a successful attacker do?
An unauthorized attacker could elevate privileges in Azure AI Foundry. The supplied severity data indicates potential high impact to confidentiality, integrity, and availability, with scope change.