Junglewise Threat Intelligence

CVE-2026-32174: Microsoft Azure AI Bot Service privilege escalation

CVE-2026-32174 · Severity: high · CVSS 7.7 · Published 2026-06-18

Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Azure AI Bot Service could allow an authorized user to gain higher-level permissions than they should have. Azure Bot Service is a platform used by organizations to build and manage intelligent conversational bots. If exploited, an attacker with basic access could manipulate service settings or data, potentially disrupting bot operations or bypassing organizational controls.

Technical details

An improper authentication vulnerability (CWE-287) exists in the Microsoft Azure AI Bot Service. The flaw allows an attacker who is already authenticated to the network with low-level privileges to elevate their permissions. According to the CVSS vector, the attack can be executed remotely over the network without user interaction, and it has a 'Changed' scope, indicating the impact may extend beyond the immediate Bot Service component to other integrated resources. The primary impact is on data and system integrity. Microsoft has addressed this in their hosted service environment.

Affected products

  • Microsoft Azure AI Bot Service All versions

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References