DIRAS TAKE
Urgent: this flaw allows unauthenticated access to privileged functions, so restrict network exposure now and apply the vendor's update or guidance immediately when available.
What is CVE-2026-85889?
An unauthenticated remote attacker can perform privilege elevation against Azure AI Foundry under CVE-2026-85889, allowing actions that require higher privileges. The flaw is a missing authentication control (CWE-306) in Azure AI Foundry; vendor information lists the product branch as affected but does not enumerate fixed versions. An attacker needs network access to the service and does not require valid credentials or user interaction to exploit the issue. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Azure AI Foundry are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Azure AI Foundry | - |
Is CVE-2026-85889 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-85889
- Follow Microsoft guidance and apply the vendor patch or update as released for Azure AI Foundry.
- Isolate Azure AI Foundry instances from untrusted networks and block unnecessary inbound access.
- Require network-level authentication or access controls (VPN, firewall rules) around the service until patched.
- Monitor logs and alerts for unexpected privilege changes or administrative activity on Azure AI Foundry.
Frequently asked questions
Is CVE-2026-85889 being actively exploited?
There are no public reports of active exploitation of CVE-2026-85889 as of 2026-09-29.
Which Azure AI Foundry versions are affected by CVE-2026-85889?
Microsoft lists the Azure AI Foundry product branch as affected but has not published specific fixed-version identifiers in the data provided here; consult Microsoft security advisories for exact version details.
Is there a patch for CVE-2026-85889?
A patch is reported available for Azure AI Foundry; administrators should follow Microsoft's update instructions to obtain and install the remediation for their deployments.
Does CVE-2026-85889 require authentication?
No. The vulnerability is a missing authentication control in Azure AI Foundry (CWE-306), so exploitation does not require valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-85889
- cve.org/CVERecord?id=CVE-2026-85889
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026