T

Threats

Microsoft Purview Data Governance SSRF Vulnerability

Overview

  • CVE: CVE-2026-57106

  • Severity: Critical

  • CVSS: 10.0

  • Published: 24 July 2026

  • Updated: 26 July 2026

  • Product: Microsoft Purview Data Governance, Data Quality

Microsoft has disclosed a critical server-side request forgery vulnerability in the Data Quality capability of Microsoft Purview Data Governance. The vulnerability allows an unauthorised attacker to elevate privileges over a network.

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. This indicates network-based exploitation with low attack complexity, no privileges required, no user interaction, a changed security scope, and high potential impact to confidentiality, integrity and availability.


Affected Versions

Microsoft Purview Data Governance, Data Quality

  • Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.

  • Fixed: Microsoft references an official fix, but has not published a fixed version identifier in the CVE record.

  • Not affected: Microsoft has not identified unaffected versions, platforms or configurations.

  • Source: Microsoft Security Response Center - CVE-2026-57106


Vulnerability Breakdown

CVE-2026-57106 - Data Quality Server-Side Request Forgery

  • Severity: Critical

  • CVSS: 10.0

  • CWE: CWE-918, Server-Side Request Forgery

  • Description: A server-side request forgery flaw in Microsoft Purview Data Governance Data Quality allows an unauthorised attacker to cause unintended server-side requests and elevate privileges over a network.

  • Impact: Successful exploitation could compromise confidentiality, integrity and availability across a changed security scope.

  • Conditions: Network access is required. Attack complexity is low, with no existing privileges and no user interaction required.

  • Exploit maturity: The CVE record reports exploit code maturity as unproven and remediation level as an official fix.

Mitigation

  • Review the Microsoft Security Response Center advisory for CVE-2026-57106.

  • Apply the official Microsoft remediation referenced in the advisory as soon as it is available to your environment.

  • Confirm that Microsoft Purview Data Governance and its Data Quality capability are covered by your organisation's cloud vulnerability and change-management processes.

  • Escalate to Microsoft support if you cannot confirm the remediation state of your Purview environment.


Summary for IT Teams

  • Product: Microsoft Purview Data Governance, Data Quality

  • Threat Level: Critical, CVSS 10.0

  • Action Required: Review the Microsoft advisory immediately, confirm the official remediation has been applied to the service, and validate the remediation state through your standard cloud security process.


Reference


Need Help?

Secure ISS can help your organisation assess exposure, validate remediation and strengthen Microsoft Purview security controls. Contact the Secure ISS SOC team on 1300 769 460 or email us for assistance.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.