high · CVSS v3 8.6
CVE-2026-68791
CVE-2026-68791 is a high-severity authorization flaw in Azure Machine Learning that can allow an unauthorized remote actor to disclose infor
Overview
CVE-2026-68791 is a high-severity authorization flaw in Azure Machine Learning that can allow an unauthorized remote actor to disclose information over the network. It matters because Azure ML workloads may contain sensitive training data, model artifacts, credentials, or operational metadata. Defenders should treat this as a potential confidentiality exposure until Microsoft guidance and patching are confirmed.
Description
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
Impact
The primary impact is confidentiality, with possible exposure of Azure Machine Learning resources, datasets, model metadata, or related configuration information. Impacted parties include Azure tenants, data scientists, ML engineers, and administrators responsible for Azure ML workspaces, experiments, or model registries. Availability and integrity are not described in the provided summary, but exposed information could support further reconnaissance or follow-on access attempts. Defensive priority should focus on limiting unauthorized access and detecting anomalous read activity.
Remediation
Apply Microsoft security updates or configuration changes for Azure Machine Learning as soon as they are published. Review workspace, dataset, model, and storage authorization settings to ensure least privilege and remove unnecessary access. Restrict network exposure of Azure ML endpoints and management surfaces using private endpoints, network security groups, or Azure Private Link where supported. Enable and review Azure Monitor, Activity Log, and storage access logs for unusual reads or authorization anomalies. Rotate credentials, keys, or tokens if sensitive Azure ML resources may have been exposed.
Risk context
The reported CVSS v3 score is 8.6, indicating high severity, but no EPSS value is provided. Urgency should be elevated for internet-exposed Azure Machine Learning environments or workspaces containing sensitive data. If Microsoft has released a patch or guidance, prioritize remediation based on asset criticality and exposure.
Affected products
- Microsoft Azure Machine Learning
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 8.6
- CVSS v4
- —
- EPSS
- —