CRITICAL9.8
PYSEC-2026-289
Azure AI Language Authoring Elevation of Privilege Vulnerability can Lead to RCE
Quick fix
PYSEC-2026-289 — azure-ai-language-conversations-authoring: upgrade to the fixed version with the command below.
pip install --upgrade 'azure-ai-language-conversations-authoring>=1.0.0b4'Details
Deserialization of untrusted data in the Azure AI Language Conversations Authoring client library for Python allows an unauthorized attacker to execute code over a network.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/azure-ai-language-conversations-authoring
Introduced in:
0Fixed in: 1.0.0b4Fix
pip install --upgrade 'azure-ai-language-conversations-authoring>=1.0.0b4'References
- https://nvd.nist.gov/vuln/detail/CVE-2026-21531[ADVISORY]
- https://github.com/Azure/azure-sdk-for-python[PACKAGE]
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21531[WEB]
- https://pypi.org/project/azure-ai-language-conversations-authoring[PACKAGE]
- https://github.com/advisories/GHSA-436v-jg82-p533[ADVISORY]