What is CVE-2026-56167?
This vulnerability in Azure AI Search allows an authorized attacker to elevate privileges over a network by exploiting a Server-Side Request Forgery (SSRF) flaw. Affected Azure AI Search users should immediately apply the security updates provided by Microsoft.
Azərbaycanca: Azure AI Search xidmətində aşkar edilmiş bu boşluq avtorizasiyalı hücumçuya Server-Side Request Forgery (SSRF) zəifliyi vasitəsilə şəbəkə üzərindən imtiyazlarını yüksəltməyə imkan verir. Təsirə məruz qalan Azure AI Search istifadəçiləri dərhal Microsoft tərəfindən təqdim edilən təhlükəsizlik yeniləmələrini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which service is affected by CVE-2026-56167?
The vulnerability affects the Azure AI Search service.
What can an attacker achieve over a network by exploiting CVE-2026-56167?
An authorized attacker can elevate privileges by exploiting a Server-Side Request Forgery (SSRF) flaw.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.