What happened
Published alongside CVE-2026-85889 in Microsoft's Sept 17, 2026 advisory batch, this SSRF flaw in Azure AI Foundry likewise allowed unauthorized privilege elevation over the network.
Why it matters
SSRF in a cloud AI orchestration platform can be used to reach internal metadata endpoints or services, compounding the risk from the co-disclosed critical auth-bypass bug on the same platform.
Attack vector
Server-side request forgery in Azure AI Foundry allows an unauthorized attacker to elevate privileges over the network, likely by coercing the service into making internal requests on the attacker's behalf.
Affected systems
Azure AI Foundry (Microsoft Foundry)
Mitigation
Fully remediated server-side by Microsoft; no customer action required.