Junglewise Threat Intelligence

CVE-2026-33833: Microsoft Azure Machine Learning injection vulnerability

CVE-2026-33833 · Severity: high · CVSS 8.2 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Azure Machine Learning could allow an attacker to trick users into interacting with malicious content. Azure Machine Learning is a cloud service used by data scientists and developers to build, train, and deploy machine learning models. If exploited, an attacker could spoof legitimate communications or interfaces, potentially leading to the theft of sensitive information or unauthorized access to user accounts.

Technical details

An injection vulnerability (CWE-74) exists in Microsoft Azure Machine Learning due to improper neutralization of special elements in output passed to downstream components. An unauthenticated attacker can exploit this over the network by sending specially crafted data that results in spoofing. While the attack vector is network-based, it requires user interaction (UI:R) and results in a scope change (S:C), indicating the vulnerability may allow the attacker to impact components beyond the immediate security scope of the application. Successful exploitation primarily impacts confidentiality (C:H) and integrity (I:L). Microsoft has addressed this in version 1.7.6.

Affected products

  • Microsoft Azure Machine Learning 3.0.0 up to (but not including) 1.7.6

Timeline

  • 2026-05-12: advisory: Initial publication by Microsoft and NVD
  • 2026-06-18: other: NIST initial analysis and CPE configuration added

References

Related threats