Description
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-02
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery in Azure OpenAI, allowing an authenticated user to instruct the service to make requests to internal network endpoints. This capability effectively elevates the attacker’s privileges within the organization, enabling them to bypass normal access controls, access protected resources, and potentially compromise confidentiality or integrity. The flaw is classified as CWE‑918, reflecting a lack of proper validation of URLs used server‑side.

Affected Systems

Microsoft Azure OpenAI services are affected. No specific version information is available; all deployments are considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS base score of 9.9 indicates a critical severity, while the EPSS score of less than 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. Because the SSRF can be triggered by users who already have legitimate access to Azure OpenAI, the attack surface is broadened, allowing the attacker to pivot to other internal services and expand their foothold within the network.

Generated by OpenCVE AI on July 21, 2026 at 10:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure OpenAI patch from the Microsoft update guide immediately
  • Restrict outbound requests from the Azure OpenAI service to a whitelist of approved endpoints
  • Enforce least‑privilege IAM roles for users who interact with Azure OpenAI so that a successful SSRF has minimal impact

Generated by OpenCVE AI on July 21, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft azure Open-ai
Vendors & Products Microsoft azure Open-ai

Thu, 02 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Title Azure OpenAI Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Open-ai
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:azure_open-AI:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Open-ai
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Open-ai Azure Open-ai
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-23T23:55:07.776Z

Reserved: 2026-05-12T16:07:22.619Z

Link: CVE-2026-45499

cve-icon Vulnrichment

Updated: 2026-07-06T11:54:00.661Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)