VDB
Sign up
CRITICAL9.8

PYSEC-2026-289

Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE

Quick fix

PYSEC-2026-289 — azure-ai-language-conversations-authoring: upgrade to the fixed version with the command below.

pip install --upgrade 'azure-ai-language-conversations-authoring>=1.0.0b4'

Details

Deserialization of untrusted data in the Azure AI Language Conversations Authoring client library for Python allows an unauthorized attacker to execute code over a network.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/azure-ai-language-conversations-authoring
Introduced in: 0Fixed in: 1.0.0b4
Fixpip install --upgrade 'azure-ai-language-conversations-authoring>=1.0.0b4'

References