Vulnerability  ·  2026-07-25

Azure AI Search SSRF Enables Privilege Escalation

VulnerabilityHigh impactGlobalCVE-2026-56167
Microsoft published CVE-2026-56167 (July 24, 2026) disclosing an SSRF vulnerability in Azure AI Search that allows an authorized attacker to pivot to elevated privileges over the network, affecting the managed cloud service that underlies many enterprise RAG/vector-search AI deployments.
Azure AI Search is a core managed component in many enterprise generative-AI/RAG architectures; an SSRF-driven privilege escalation in this service could let an attacker with limited access pivot into internal Azure network resources or escalate control over the AI search backend feeding production LLM applications.
An authorized attacker exploits a server-side request forgery in Azure AI Search to elevate privileges over the network, per Microsoft's advisory (CVSS 8.5, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Azure AI Search (Microsoft cloud service)
Apply Microsoft's fix per MSRC advisory; Microsoft has published patches as part of standard Azure service update (cloud service — no customer action required beyond standard Azure security hygiene per MSRC guidance).
Microsoft Security Response CenterTenable CVE-2026-56167
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →