Junglewise Threat Intelligence

CVE-2026-85889: Microsoft Azure AI Foundry missing authentication for critical function

CVE-2026-85889 · Severity: critical · CVSS 10 · Published 2026-09-17

Vendors: Microsoft.

Executive brief

Azure AI Foundry, Microsoft's platform for building and deploying AI applications, contains a missing authentication check in a critical function. An attacker with network access can exploit this to gain unauthorized administrative privileges without credentials, potentially compromising all AI models, data, and applications within the environment.

Technical details

A critical function in Azure AI Foundry lacks proper authentication checks, allowing unauthenticated network-based privilege escalation. The vulnerability requires only network access and no valid credentials to exploit. Successful exploitation grants full administrative control over the affected AI Foundry instance.

Affected products

  • Microsoft Azure AI Foundry

Timeline

  • 2026-09-17: disclosed

References

Related threats