Missing Authentication in Microsoft Azure AI Foundry Enables Privilege Escalation
AI analysis
CVE-2026-85889 is a missing authentication flaw (CWE-306) in Microsoft Azure AI Foundry, meaning a critical function can be reached without any credential check. An unauthenticated attacker can trigger it remotely over a network with no user interaction and no privileges required. Successful exploitation allows the attacker to elevate privileges, and the CVSS scope-change designation (S:C) indicates the impact can extend beyond the initially compromised security authority, with high confidentiality, integrity, and availability impact. Any organization using Azure AI Foundry is potentially affected, though the flaw is in a Microsoft-managed cloud platform rather than a customer-deployed package. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known.
What to do: Because Azure AI Foundry is a Microsoft-managed service, monitor Microsoft's security advisory and Azure Service Health for patched status and any customer-required actions rather than applying your own patch. In the meantime, review role assignments, API keys, and network access controls (firewalls, private endpoints, virtual-network restrictions) on your Foundry resources, and check Azure activity logs for unauthenticated or anomalous privilege-related operations. Rotate credentials if suspicious activity is found and watch for updates, as a CVSS 10.0 flaw may draw rapid attacker attention.
Affected
| Microsoft Azure AI Foundry | — |
Estimated exposure
large≈70,000+ organizations, likely hundreds of thousands of developer users (Microsoft-cited platform adoption) — Microsoft has publicly cited adoption of Azure AI Foundry by tens of thousands of organizations, but the subset whose deployments touch the vulnerable function is unknown since this is a hosted cloud service.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.