Executive brief
Azure AI Foundry, Microsoft's platform for building and deploying AI applications, contains a missing authentication check in a critical function. An attacker with network access can exploit this to gain unauthorized administrative privileges without credentials, potentially compromising all AI models, data, and applications within the environment.
Technical details
A critical function in Azure AI Foundry lacks proper authentication checks, allowing unauthenticated network-based privilege escalation. The vulnerability requires only network access and no valid credentials to exploit. Successful exploitation grants full administrative control over the affected AI Foundry instance.
Affected products
- Microsoft Azure AI Foundry
Timeline
- 2026-09-17: disclosed