ZeroHour

CVE-2026-85889

large

Missing Authentication in Microsoft Azure AI Foundry Enables Privilege Escalation

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-85889 is a missing authentication flaw (CWE-306) in Microsoft Azure AI Foundry, meaning a critical function can be reached without any credential check. An unauthenticated attacker can trigger it remotely over a network with no user interaction and no privileges required. Successful exploitation allows the attacker to elevate privileges, and the CVSS scope-change designation (S:C) indicates the impact can extend beyond the initially compromised security authority, with high confidentiality, integrity, and availability impact. Any organization using Azure AI Foundry is potentially affected, though the flaw is in a Microsoft-managed cloud platform rather than a customer-deployed package. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known.

What to do: Because Azure AI Foundry is a Microsoft-managed service, monitor Microsoft's security advisory and Azure Service Health for patched status and any customer-required actions rather than applying your own patch. In the meantime, review role assignments, API keys, and network access controls (firewalls, private endpoints, virtual-network restrictions) on your Foundry resources, and check Azure activity logs for unauthenticated or anomalous privilege-related operations. Rotate credentials if suspicious activity is found and watch for updates, as a CVSS 10.0 flaw may draw rapid attacker attention.

Affected
Microsoft Azure AI Foundry
Estimated exposure
large≈70,000+ organizations, likely hundreds of thousands of developer users (Microsoft-cited platform adoption) — Microsoft has publicly cited adoption of Azure AI Foundry by tens of thousands of organizations, but the subset whose deployments touch the vulnerable function is unknown since this is a hosted cloud service.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft patched a CVSS 10.0 missing-authentication privilege escalation flaw, CVE-2026-85889, in Azure AI Foundry, already fully mitigated server-side.

Microsoft fixed CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry (Microsoft Foundry) that allows unauthorized attackers to elevate privileges over a network, credited to researcher Rémy Marot. No exploitation in the wild was reported, and Microsoft says these cloud flaws are fully mitigated with no customer action required. The same effort covered CVE-2026-85885 (CVSS 9.9 command injection in Microsoft 365 Copilot), CVE-2026-85878 (CVSS 9.9 Azure Database for PostgreSQL), and CVE-2026-87701 (CVSS 9.6 Azure Cosmos DB). Out-of-band Windows 11 26H1 updates (KB5129194) also address local privilege escalation flaws CVE-2026-62721 and CVE-2026-85921.

Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges

Microsoft patched CVE-2026-85889 (CVSS 10.0), a missing-auth flaw in Azure AI Foundry enabling unauthenticated network privilege escalation; no exploitation observed.

CVE-2026-85889, rated 10.0, stems from a missing authentication check (CWE-306) in Azure AI Foundry, letting unauthenticated attackers abuse a backend function and bypass access controls. Microsoft deployed a server-side fix, so no customer action is required, and reports no active exploitation or public PoC. The advisory window also included CVE-2026-85885 in Microsoft 365 Copilot and CVE-2026-85878 in Azure Database for PostgreSQL, both rated 9.9.