Executive brief
Azure AI Foundry is a platform used by organizations to build, deploy, and manage artificial intelligence models and applications. A critical security flaw allows an unauthorized person to gain elevated administrative permissions over the network without needing any existing login credentials. This could lead to a total compromise of the AI environment, including the theft of sensitive training data, modification of AI models, or complete service disruption.
Technical details
A critical improper authorization vulnerability (CWE-285/CWE-863) exists in Azure AI Foundry, a cloud-based platform for AI development. The flaw allows a remote, unauthenticated attacker to bypass authorization checks and escalate their privileges within the service. According to the CVSS vector, the attack is low complexity, requires no user interaction, and has a 'Changed' scope, indicating the attacker may be able to impact resources beyond the immediate security scope of the vulnerable component. As an exclusively hosted service, Microsoft typically manages the remediation on the backend, though users should verify their environment configurations via the MSRC update guide.
Affected products
- Microsoft Azure AI Foundry All versions
Timeline
- 2026-04-02: disclosed: Initial disclosure by Microsoft Corporation
- 2026-04-03: advisory: NVD publication date