Junglewise Threat Intelligence

CVE-2026-56167: Microsoft Azure AI Search server-side request forgery

CVE-2026-56167 · Severity: high · CVSS 8.5 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Azure AI Search, a cloud-based search service used to power search functionality in applications. An authorized user could exploit this flaw to trick the server into making unauthorized requests to internal or external systems. This could allow an attacker to gain higher levels of access than intended, potentially leading to the exposure of sensitive internal data.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Microsoft Azure AI Search (formerly Azure Cognitive Search). The flaw, classified as CWE-918, allows an authenticated attacker with low-level privileges to send specially crafted network requests from the search service. By exploiting this vulnerability, an attacker can achieve a 'Scope' change (as indicated by the CVSS vector), allowing them to access resources or metadata services that should be isolated from the user. This can lead to unauthorized privilege escalation and high-impact data confidentiality loss. As this is an exclusively hosted cloud service, Microsoft typically manages the remediation on the backend.

Affected products

  • Microsoft Azure AI Search All versions

Timeline

  • 2026-07-24: advisory: Initial advisory published by Microsoft and NVD.

References