PT-2026-38576 · Microsoft · Azure Machine Learning

Jianyang Song

·

Published

2026-05-07

·

Updated

2026-05-12

·

CVE-2026-32207

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Azure Machine Learning (affected versions not specified)
Description Improper neutralization of input during web page generation in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. This issue is a form of cross-site scripting (XSS), which occurs when an application includes untrusted data in a web page without proper validation or encoding.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-06465
CVE-2026-32207

Affected Products

Azure Machine Learning