Executive brief
Azure AI Foundry, Microsoft's platform for building and managing AI applications, contains a server-side request forgery (SSRF) vulnerability that allows an attacker to make unauthorized requests from the server. An attacker can exploit this to access internal resources or sensitive data, potentially escalating their privileges within the Azure environment.
Technical details
The vulnerability is a server-side request forgery in Azure AI Foundry that permits privilege escalation over a network from an unauthenticated attacker position. The SSRF flaw allows an attacker to craft requests that the server will execute against internal resources, potentially bypassing authentication controls and accessing restricted endpoints or data. Exploitation requires network access to the affected service.
Affected products
- Microsoft Azure AI Foundry
Timeline
- 2026-09-17: disclosed