🟠 High  |  Source: Microsoft Security Response Center


A server-side request forgery (SSRF) vulnerability in Azure AI Search allows an attacker who already has some level of authorised access to escalate their privileges over a network. This could enable them to access resources or perform actions beyond their intended permissions. The risk is particularly significant in multi-tenant or shared Azure AI Search deployments where privilege boundaries are critical.

Security Architect’s Take: Review and tighten network access controls around Azure AI Search endpoints, applying private endpoints and restricting outbound network access where possible. Monitor Microsoft’s update guidance for patches or mitigations and assess whether any authorised users could abuse this to reach sensitive downstream resources.

Original advisory: CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability