type: cve · created: 2026-09-19 · updated: 2026-09-19 · tags: [cve] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Microsoft has fixed a maximum-severity flaw in Azure AI Foundry — CVE-2026-85889, CVSS 10.0 — described as "missing authentication for critical function" that allows an unauthorised attacker to elevate privileges over a network.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-85889 |
| CVSS | 10.0 (critical) |
| Vendor / product | Microsoft — Azure AI Foundry (Microsoft Foundry) |
| Reported | 2026-09-19 |