Vulnerability  ·  2026-09-19

Azure AI Foundry — SSRF enabling unauthenticated privilege escalation

VulnerabilityHigh impactGlobalCVE-2026-85917
Published alongside CVE-2026-85889 in Microsoft's Sept 17, 2026 advisory batch, this SSRF flaw in Azure AI Foundry likewise allowed unauthorized privilege elevation over the network.
SSRF in a cloud AI orchestration platform can be used to reach internal metadata endpoints or services, compounding the risk from the co-disclosed critical auth-bypass bug on the same platform.
Server-side request forgery in Azure AI Foundry allows an unauthorized attacker to elevate privileges over the network, likely by coercing the service into making internal requests on the attacker's behalf.
Azure AI Foundry (Microsoft Foundry)
Fully remediated server-side by Microsoft; no customer action required.
Microsoft Security Response Center advisoryNVD CVE-2026-85917
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →