high · CVSS v3 7.5
CVE-2026-85917
CVE-2026-85917 is a high-severity server-side request forgery issue in Microsoft Azure AI Foundry. It could allow an unauthorized network at
Overview
CVE-2026-85917 is a high-severity server-side request forgery issue in Microsoft Azure AI Foundry. It could allow an unauthorized network attacker to trigger requests that lead to privilege escalation. It matters because cloud AI services often have broad network access and can be a pivot point into internal resources.
Description
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Impact
The vulnerability primarily affects confidentiality and integrity, with potential availability impact if internal services are disrupted. It could expose sensitive internal endpoints, credentials, or metadata to unauthorized actors. Tenants with internet-facing Azure AI Foundry deployments, integrated applications, or broad service permissions are most at risk. Privileged administrators and downstream systems that trust Azure AI Foundry responses may also be impacted.
Remediation
Apply Microsoft’s published patch or service update for Azure AI Foundry as soon as it is available. Restrict outbound network access from Azure AI Foundry to only required destinations using network security groups, private endpoints, or service-level egress controls. Enforce least-privilege IAM roles and review service principals, managed identities, and API permissions. Monitor Azure Activity, network flow logs, and application logs for unusual outbound requests or privilege changes, and rotate credentials if compromise is suspected.
Risk context
CVSS v3 is 7.5, which is high severity. No EPSS score is provided, so urgency should be driven by exposure, internet reachability, and sensitivity of connected resources. Defenders should prioritize environments where Azure AI Foundry can reach internal services or hold elevated permissions.
Affected products
- Microsoft Azure AI Foundry
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —