Description
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-07-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery (CWE‑918) within the Data Quality component of Microsoft Purview Data Governance. An unauthenticated attacker can cause the service to make internal network requests that the attacker does not normally have permission to perform, effectively allowing escalation of privileges across the network.

Affected Systems

Affected systems include Microsoft Purview Data Governance. No version numbers are disclosed in this advisory, so all deployments of the product that include the Data Quality feature are considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to submit a request to the Data Quality service that triggers an internal call, which could be exploited if the service fails to validate target URLs or restricts outbound traffic.

Generated by OpenCVE AI on August 3, 2026 at 20:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Purview Data Governance update following the Microsoft Security update guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57106).
  • Restrict outbound network requests from the Data Quality service to only whitelisted IPs or domains, preventing unintended internal service calls.
  • Enable logging and monitoring for inbound requests to the Data Quality component and review for anomalous internal requests, alerting on repeated unauthenticated access attempts.

Generated by OpenCVE AI on August 3, 2026 at 20:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Title Data Quality Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft office Purview Data Governance
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:office_purview_data_governance:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft office Purview Data Governance
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Microsoft Office Purview Data Governance Purview Data Governance
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:32.422Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57106

cve-icon Vulnrichment

Updated: 2026-07-24T15:31:31.091Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T15:18:39.633

Modified: 2026-07-29T15:00:03.353

Link: CVE-2026-57106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:15:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)