What happened
Microsoft disclosed and patched CVE-2026-85889 (CVSS 10.0, CWE-306 Missing Authentication for Critical Function) in Azure AI Foundry, allowing an unauthorized network attacker to elevate privileges without any prior access. Microsoft found no evidence of pre-patch exploitation and credited researcher Rémy Marot for discovery.
Why it matters
Azure AI Foundry is Microsoft's flagship generative-AI/agent platform; an unauthenticated privilege-escalation path in its orchestration layer could have let an attacker manipulate models, training data, or agent workflows across any tenant before the fix shipped, representing maximum-severity exposure in widely-deployed cloud AI infrastructure.
Attack vector
A critical function in Azure AI Foundry lacked any authentication check, allowing an unauthenticated network attacker to elevate privileges within the service — potentially impacting model integrity, training datasets, and privileged orchestration operations.
Affected systems
Azure AI Foundry (Microsoft Foundry) — all customer tenants prior to Microsoft's server-side patch
Mitigation
Fully remediated server-side by Microsoft on Sept 17, 2026; no customer action required. Security teams should review Azure AI Foundry audit logs for anomalous access patterns, privilege assignments, and API calls predating the patch as a precaution.