Junglewise Threat Intelligence

CVE-2026-68791: Microsoft Azure Machine Learning incorrect authorization

CVE-2026-68791 · Severity: high · CVSS 8.6 · Published 2026-09-17

Vendors: Microsoft.

Executive brief

Microsoft Azure Machine Learning contains an authorization flaw that allows an attacker to access information without proper credentials over the network. This vulnerability could lead to unauthorized disclosure of sensitive data stored or processed within the Machine Learning service, potentially exposing customer models, training data, or other confidential information.

Technical details

The vulnerability is an incorrect authorization issue in Azure Machine Learning that enables information disclosure over a network vector. An attacker can exploit this authorization bypass to access data or functionality without proper authentication or permission checks. The vulnerability does not require user interaction or specialized preconditions beyond network access to the affected service. There is no evidence of active exploitation in the wild as of the advisory date. A security update is expected to be available from Microsoft.

Affected products

  • Microsoft Azure Machine Learning

Timeline

  • 2026-09-17: disclosed

References

Related threats