Junglewise Threat Intelligence

CVE-2026-85917: Microsoft Azure AI Foundry server-side request forgery

CVE-2026-85917 · Severity: high · CVSS 7.5 · Published 2026-09-17

Technologies: Microsoft Azure Ai Foundry. Vendors: Microsoft.

Executive brief

Azure AI Foundry, Microsoft's platform for building and managing AI applications, contains a server-side request forgery (SSRF) vulnerability that allows an attacker to make unauthorized requests from the server. An attacker can exploit this to access internal resources or sensitive data, potentially escalating their privileges within the Azure environment.

Technical details

The vulnerability is a server-side request forgery in Azure AI Foundry that permits privilege escalation over a network from an unauthenticated attacker position. The SSRF flaw allows an attacker to craft requests that the server will execute against internal resources, potentially bypassing authentication controls and accessing restricted endpoints or data. Exploitation requires network access to the affected service.

Affected products

  • Microsoft Azure AI Foundry

Timeline

  • 2026-09-17: disclosed

References

Related threats