CVE-2026-85917: Azure AI Foundry Elevation of Privilege Vulnerability
Published Sep 17, 2026
·Updated
Azure AI Foundry Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure AI Foundry
Microsoft Azure AI Foundry
Event History
Sep 17, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:55 PM
Data Sourced
via MITRE·10:55 PM
DescriptionSeverity
Frequently Asked Questions
1
Does exploiting this issue require credentials or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
2
What is the expected security impact if exploitation succeeds?
The supplied severity data indicates high confidentiality impact, with no integrity or availability impact listed. The vulnerability is described as enabling elevation of privilege.
3
Which environments should be assessed for exposure?
Assess deployments using Microsoft Azure AI Foundry. The provided data does not identify affected versions, configurations, or specific components.