Description
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-02
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server-side request forgery in Azure OpenAI, classified as CWE‑918. It permits an authenticated user to instruct the service to make requests to internal network endpoints, effectively elevating the attacker’s privileges and potentially bypassing normal access controls. This can lead to unauthorized access to protected resources and compromise the confidentiality, integrity, or availability of internal systems.

Affected Systems

All Microsoft Azure OpenAI services are affected. No specific version information is available; every deployment that has not been updated with the latest security patch is considered vulnerable until the patch is applied.

Risk and Exploitability

The CVSS base score of 9.9 indicates a critical severity. The EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits. Based on the description, it is inferred that the SSRF can only be triggered by users who already have legitimate access to Azure OpenAI, meaning the attack surface requires authenticated users but can still be leveraged to pivot to other internal services. The critical score combined with a limited attack surface underscores the need for urgent remediation.

Generated by OpenCVE AI on July 31, 2026 at 14:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure OpenAI patch from the Microsoft update guide immediately
  • Restrict outbound requests from the Azure OpenAI service to a whitelist of approved endpoints
  • Enforce least-privilege IAM roles for users who interact with Azure OpenAI to limit the impact of a successful SSRF

Generated by OpenCVE AI on July 31, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft azure Open-ai
Vendors & Products Microsoft azure Open-ai

Thu, 02 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Title Azure OpenAI Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Open-ai
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:azure_open-AI:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Open-ai
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Open-ai Azure Open-ai Azure Openai
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:15:02.633Z

Reserved: 2026-05-12T16:07:22.619Z

Link: CVE-2026-45499

cve-icon Vulnrichment

Updated: 2026-07-06T11:54:00.661Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T23:16:51.003

Modified: 2026-07-07T14:04:54.607

Link: CVE-2026-45499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T15:00:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)