Description
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow in Microsoft Fabric Data Warehouse enables a remote attacker with authorized access to execute arbitrary code over the network. The flaw occurs when the system processes input that exceeds the allocated stack buffer, allowing memory corruption and arbitrary code execution. It is a classic stack overflow defect (CWE-121).

Affected Systems

This vulnerability affects Microsoft Service Fabric’s Fabric Data Warehouse component. No specific version information is listed, so any installation of the Fabric Data Warehouse may be impacted until updated.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is below 1% suggesting a low probability of being exploited in the wild, and it is not included in the CISA KEV catalog. Attack vectors are likely through network communication with the Fabric Data Warehouse service, and exploitation requires approved credentials or privileged access as implied by the description.

Generated by OpenCVE AI on July 31, 2026 at 06:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft Security Update for Fabric Data Warehouse as published by Microsoft via the MSRC link.
  • Reduce the attack surface by disabling or restricting remote interfaces exposed by Fabric Data Warehouse to only trusted internal networks.
  • Configure network‑level access controls and firewall rules to limit inbound traffic to the service.
  • Enable detailed logging and monitor for unusual activity or repeated failed authentication attempts.

Generated by OpenCVE AI on July 31, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft service Fabric
Vendors & Products Microsoft
Microsoft service Fabric

Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
Title Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability
First Time appeared Fabric
Fabric data Warehouse
Weaknesses CWE-121
CPEs cpe:2.3:a:fabric:data_warehouse:*:*:*:*:*:*:*:*
Vendors & Products Fabric
Fabric data Warehouse
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Fabric Data Warehouse
Microsoft Service Fabric
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:27:03.388Z

Reserved: 2026-06-22T15:17:38.795Z

Link: CVE-2026-56642

cve-icon Vulnrichment

Updated: 2026-07-15T13:06:33.265Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:30:18Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow