Executive brief
A critical security vulnerability has been identified in Microsoft Azure OpenAI, a cloud-based service used to deploy and manage artificial intelligence models. An attacker with basic access to the service could trick the system into making unauthorized requests to internal resources, potentially leading to a full takeover of the environment or access to sensitive data. This could result in significant data breaches or disruption of AI-driven business operations.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Microsoft Azure OpenAI. The flaw allows an authenticated attacker with low privileges to send specially crafted network requests from the Azure OpenAI infrastructure. Because the vulnerability results in a scope change (CVSS Scope: Changed), the attacker can leverage this to access internal metadata services or other protected resources, ultimately leading to a full elevation of privileges. The attack is reachable over the network and requires no user interaction. As this is an exclusively hosted service, Microsoft typically manages the remediation on the backend.
Affected products
- Microsoft Azure OpenAI Service All versions
Timeline
- 2026-07-02: advisory: Initial advisory published by Microsoft and NVD.