Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-85889

Azure AI Foundry missing authentication allows unauthorized privilege escalation

Missing authentication for a critical function in Azure AI Foundry lets an unauthenticated attacker escalate privileges over a network. CVSS 10.0 critical; Microsoft patched on the service side with no customer action required.

cat cve-2026-85889.json
Vendor
Microsoft
Product
Azure AI Foundry
CVSS
10.0
EPSS (exploit probability)
0.5%
Status
patched
Published

A missing-authentication condition on a critical function in Azure AI Foundry allowed an unauthenticated attacker to escalate privileges over a network. Microsoft assigned CVSS 10.0 and patched the vulnerability on the service side; no action is required from Azure AI Foundry customers.

Refer to the MSRC advisory for the official disclosure. If your organization runs workloads on Azure AI Foundry, review activity logs for anomalous access from the period before the patch, though Microsoft has not confirmed active exploitation.