Cyber & AI intelligence
Wasteland.
Briefs indexed2403
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-70352 2026-09-03

CVE-2026-70352: Missing Authentication in Azure AI Language Authoring

"Microsoft has disclosed a critical missing-authentication flaw in Azure AI Language Authoring that lets an unauthenticated remote attacker elevate privileges, rated CVSS 10.0."

Microsoft has disclosed a critical missing-authentication flaw in Azure AI Language Authoring that lets an unauthenticated remote attacker elevate privileges, rated CVSS 10.0.

What Is It

CVE-2026-70352 is a missing authentication for a critical function (CWE-306) in Azure AI Language. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network." The CVE was published on 2026-09-03 with a source identifier of [email protected] and currently carries an NVD status of "Received," meaning analysis is still in progress.

Why It Matters

The CVSS 3.1 base score is 10.0, CRITICAL, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Every exploitability dimension is maximally favorable to an attacker: network attack vector, low attack complexity, no privileges required, and no user interaction. The exploitability subscore is 3.9, the highest possible. Scope is Changed, meaning impact extends beyond the vulnerable component's security authority, and confidentiality, integrity, and availability impacts are all High (impact subscore 6.0).

A missing-authentication bug on a critical function, reachable over the network with zero prerequisites, is a low bar to exploitation.

What's Vulnerable

Microsoft lists the affected product as Azure AI Language Authoring (vendor: Microsoft), with the affected version recorded as "-"; that is, the service as a whole rather than a discrete version range. No CPE entries are currently associated with the record.

Microsoft tagged this CVE as exclusively-hosted-service. That tag indicates the vulnerability exists in a service Microsoft hosts and operates, not in software customers install and run themselves.

Patch Status

No CISA KEV entry exists for CVE-2026-70352 in the supplied data, so there is no confirmed active exploitation and no KEV-mandated remediation deadline or required action at this time.

Because the CVE is tagged as an exclusively hosted service, no customer-installable patch is identified in the source material. The only vendor resource provided is Microsoft's MSRC update guide entry, which should be consulted for current remediation guidance. The record has not been modified since publication.

Sources