Azure AI Foundry Flaw Skips Authentication on Critical Function (CVE-2026-85889)

Key Takeaways

  • Microsoft disclosed CVE-2026-85889, a CVSS 10.0 flaw in Azure AI Foundry.
  • A critical function lacked authentication, allowing network-based privilege escalation.
  • Microsoft fully mitigated the issue in its cloud service, with no customer action required.
  • No exploitation was reported.
  • Azure AI Foundry hosts enterprise generative AI applications and agents, raising the stakes of any access flaw.

A Perfect Score Nobody Wants

Microsoft disclosed CVE-2026-85889, a maximum-severity missing-authentication vulnerability in Azure AI Foundry, as part of a set of critical cloud fixes reported by The Hacker News. Microsoft mitigated the issue server-side and reported no exploitation.

What We Know

CVE-2026-85889 was published September 18, 2026 with a CVSS score of 10.0 and classified as missing authentication for a critical function. Microsoft said an unauthorized attacker could elevate privileges over a network. The flaw was reported by researcher Remy Marot.

Azure AI Foundry, also called Microsoft Foundry, is Microsoft's platform for building, deploying, and managing generative AI applications and agents. Microsoft states the vulnerability has been fully mitigated in the cloud service and that customers do not need to take action. It was disclosed alongside other critical fixes, including a CVSS 9.9 command injection flaw in Microsoft 365 Copilot.

What Could Happen

A function that should have required authentication could be reached without it. Microsoft has not published technical details, but the CWE classification and network attack vector indicate that an attacker could call a sensitive operation directly and gain privileges they should not have.

In an AI platform, elevated privileges can mean access to model deployments, agent configurations, connected data sources, prompts, and stored credentials. Because the service is multi-tenant and centrally operated, a flaw like this could, in principle, affect many organizations at once. There is no public proof of concept or evidence of abuse, so this assessment reflects potential exposure that was closed before it was realized.

Why It Matters

AI platforms concentrate high-value assets: models, agents, data connections, and the identities that tie them together. A maximum-severity access flaw in one of the largest enterprise AI platforms shows how much customer security depends on the provider getting basic controls right.

Microsoft's coordinated disclosure and server-side fix worked as intended. Still, customers had no visibility into the exposure while it existed, which reinforces the need for independent oversight of how AI services are configured and accessed.

PointGuard AI Perspective

Enterprises cannot patch a hosted AI platform themselves, but they can control what that platform can reach. PointGuard AI Security Posture Management continuously assesses AI services such as Azure AI Foundry for excessive permissions, exposed endpoints, and risky configurations, so a provider-side flaw meets the smallest possible blast radius.

PointGuard AI Discovery inventories AI projects, models, agents, and connected data across clouds, so teams know which workloads depend on an affected service when a CVE is announced. Trustworthy AI adoption pairs strong vendor security with independent visibility and least-privilege design.

Incident Scorecard Details

Total AISSI Score: 6.0/10

Criticality: 9, A core enterprise AI platform with access to models, agents, and connected data was affected. AISSI weighting: 25%

Propagation: 7, A multi-tenant cloud service raised the potential for broad impact across customers. AISSI weighting: 20%

Exploitability: 2, The flaw was mitigated before disclosure, with no public proof of concept or exploitation. AISSI weighting: 15%

Supply Chain: 7, The risk sat entirely within a hosted third-party Microsoft service. AISSI weighting: 15%

Business Impact: 4, Patched server-side with no customer action and no confirmed harm. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

9

Propagation

7

Exploitability

2

Supply Chain

7

Business Impact

4

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.