Microsoft was reported to have mitigated CVE-2026-85889, an authentication-bypass vulnerability in Azure AI Foundry, on the server side in mid-September 2026. The flaw involved missing authentication for a critical function; its status was described as unverified on September 18 and reported as verified by September 28.

What CVE-2026-85889 affects

CVE-2026-85889 is associated with Azure AI Foundry. The vulnerability involves a critical function that lacked an authentication check, a weakness that could allow an unauthorized attacker to elevate privileges over a network.

What the CVSS 3.1 score means

The vulnerability has a CVSS 3.1 score of 9.8. Its vector describes a network-based attack with low complexity, requiring neither privileges nor user interaction. It also rates the potential effects on confidentiality, integrity, and availability as high, with the scope unchanged.

Microsoft was also reported to have assigned the vulnerability a severity score of 10.0.

The reported server-side mitigation

The reported mitigation was applied server-side in mid-September, so it did not involve a customer-side patch. Microsoft was reported to have said users did not need to take action after the mitigation.