SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-56167

HIGH · CVSS 8.5 EPSS 0.41%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A server-side request forgery vulnerability in Azure AI Search allows authorized attackers to manipulate requests, potentially leading to unauthorized privilege escalation within the network. Organizations utilizing Azure AI Search should prioritize addressing this issue to mitigate the risk of internal network exploitation. Immediate action is recommended for teams managing sensitive data or critical infrastructure relying on this service.

CVE
CVE-2026-56167
Severity
HIGH
CVSS
8.5
EPSS
0.41%

Original NVD Description

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)