• PATCH AVAILABLE

CVE-2026-70352: missing authentication in Microsoft Azure AI Language Authoring

Remote attackers can elevate privileges against Azure AI Language Authoring without authenticating. CVE-2026-70352 is a missing-authentication vulnerability (CWE-306) that allows an unauthenticated actor with network access to invoke a critical function and gain high-impact control over the affected Azure AI Language Authoring service. The vendor branch is listed as Azure AI Language Authoring; the advisory does not list specific fixed versions. An attacker needs only network access and no user interaction or credentials to exploit the flaw as described in the public data.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00921
CWE
CWE-306
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — this flaw requires no authentication and enables remote privilege elevation, so treat it as high priority; apply Microsoft’s updates or mitigations immediately and restrict network exposure to the service.

What is CVE-2026-70352?

Remote attackers can elevate privileges against Azure AI Language Authoring without authenticating. CVE-2026-70352 is a missing-authentication vulnerability (CWE-306) that allows an unauthenticated actor with network access to invoke a critical function and gain high-impact control over the affected Azure AI Language Authoring service. The vendor branch is listed as Azure AI Language Authoring; the advisory does not list specific fixed versions. An attacker needs only network access and no user interaction or credentials to exploit the flaw as described in the public data. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Microsoft Azure AI Language Authoring are affected?

BRANCHAFFECTEDFIXED
Azure AI Language Authoring-

Is CVE-2026-70352 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-70352

  1. Apply Microsoft’s provided updates or vendor guidance for Azure AI Language Authoring as soon as they are available.
  2. Restrict network exposure to the Azure AI Language Authoring endpoint; allow access only from trusted networks and management hosts.
  3. Monitor access logs and alerts for anomalous requests to the Azure AI Language Authoring service and investigate suspicious activity.
  4. Follow vendor mitigation guidance and contact Microsoft support for confirmation of fixed versions and deployment instructions.

Frequently asked questions

Is CVE-2026-70352 being actively exploited?

There are no public reports of exploitation of CVE-2026-70352 as of 2026-09-29.

Which Azure AI Language Authoring versions are affected by CVE-2026-70352?

The advisory identifies the affected branch as Azure AI Language Authoring but does not list specific version numbers or fixed releases.

Is there a patch for CVE-2026-70352?

A patch is reported available by the vendor, but the facts do not list fixed version numbers; follow Microsoft’s guidance and install vendor updates when confirmed.

Does CVE-2026-70352 require authentication?

No; the vulnerability is a missing-authentication issue (CWE-306) and can be invoked by an unauthenticated remote actor with network access to the Azure AI Language Authoring service.

References