A critical server-side request forgery (SSRF) vulnerability has been identified in Azure OpenAI, designated as CVE-2026-45499. This vulnerability enables an authorized attacker to elevate privileges over a network by manipulating internal requests. The affected software is the azure_openai platform, which is widely used for AI-driven services. With a CVSS score of 9.9, this vulnerability poses a significant risk to organizations relying on this platform. Attackers could exploit this flaw to bypass security controls, access internal systems, or exfiltrate sensitive data. The risk level is critical, as exploitation could lead to unauthorized access and potential data breaches. Organizations using Azure OpenAI are strongly advised to apply the latest security patches and updates provided by the vendor. Additionally, network segmentation and strict access controls should be enforced to mitigate potential exploitation. It is crucial to monitor for any unusual activity and ensure that all systems are configured to minimize exposure. Immediate action is recommended to address this vulnerability and protect against potential threats.
CRITICAL
CVSS 9.9
CVE-2026-45499
2026-08-22
Critical SSRF Vulnerability in Azure OpenAI (CVE-2026-45499)
A critical server-side request forgery vulnerability in Azure OpenAI allows authorized attackers to elevate privileges over a network. This affects the azure_openai platform with a CVSS score of 9.9.