rootpwn

critical · CVSS v3 10

CVE-2026-85889

A missing authentication check in Azure AI Foundry’s critical function allows an attacker to elevate privileges across the network without c

Overview

A missing authentication check in Azure AI Foundry’s critical function allows an attacker to elevate privileges across the network without credentials. This flaw can grant full control over all resources managed by Azure AI Foundry, making it a high‑risk issue for any organization using the service. Immediate action is required to prevent potential data breaches or service disruptions.

Description

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Impact

The vulnerability compromises confidentiality, integrity, and availability of data and services within Azure AI Foundry. Unauthorized users can gain elevated rights, enabling them to read, modify, or delete sensitive data, disrupt services, or pivot to other network assets. Organizations that rely on Azure AI Foundry for AI workloads are directly impacted, as attackers could tamper with models, data, or infrastructure. Defenders must treat this as a critical threat to all Azure AI Foundry deployments.

Remediation

1. Apply the latest security update or patch released by Microsoft for Azure AI Foundry. 2. Verify that authentication is enforced for all critical endpoints; if not, restrict access via network security groups or firewall rules. 3. Enable Azure AD authentication and enforce multi‑factor authentication for all users. 4. Monitor audit logs for anomalous privilege escalation attempts and set up alerts for unauthorized access patterns. 5. Conduct a rapid review of role‑based access controls to ensure least‑privilege principles are applied.

Risk context

The CVSS v3 score of 10.0 classifies this flaw as critical, indicating a high likelihood of successful exploitation with severe impact. Although EPSS data is not available, the absence of authentication for a privilege‑escalation function warrants immediate remediation to mitigate potential widespread compromise.

Affected products

  • Microsoft Azure AI Foundry
  • Azure AI Foundry API

Scores

Severity
critical
CVSS v2
10
CVSS v3
10
CVSS v4
EPSS

Azure AI PrivilegeEscalation MissingAuth Critical NetworkSecurity

← All CVEs