T
Threats
Microsoft Purview Data Governance SSRF Vulnerability
Overview
CVE: CVE-2026-57106
Severity: Critical
CVSS: 10.0
Published: 24 July 2026
Updated: 26 July 2026
Product: Microsoft Purview Data Governance, Data Quality
Microsoft has disclosed a critical server-side request forgery vulnerability in the Data Quality capability of Microsoft Purview Data Governance. The vulnerability allows an unauthorised attacker to elevate privileges over a network.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. This indicates network-based exploitation with low attack complexity, no privileges required, no user interaction, a changed security scope, and high potential impact to confidentiality, integrity and availability.
Affected Versions
Microsoft Purview Data Governance, Data Quality
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.
Fixed: Microsoft references an official fix, but has not published a fixed version identifier in the CVE record.
Not affected: Microsoft has not identified unaffected versions, platforms or configurations.
Vulnerability Breakdown
CVE-2026-57106 - Data Quality Server-Side Request Forgery
Severity: Critical
CVSS: 10.0
CWE: CWE-918, Server-Side Request Forgery
Description: A server-side request forgery flaw in Microsoft Purview Data Governance Data Quality allows an unauthorised attacker to cause unintended server-side requests and elevate privileges over a network.
Impact: Successful exploitation could compromise confidentiality, integrity and availability across a changed security scope.
Conditions: Network access is required. Attack complexity is low, with no existing privileges and no user interaction required.
Exploit maturity: The CVE record reports exploit code maturity as unproven and remediation level as an official fix.
Mitigation
Review the Microsoft Security Response Center advisory for CVE-2026-57106.
Apply the official Microsoft remediation referenced in the advisory as soon as it is available to your environment.
Confirm that Microsoft Purview Data Governance and its Data Quality capability are covered by your organisation's cloud vulnerability and change-management processes.
Escalate to Microsoft support if you cannot confirm the remediation state of your Purview environment.
Summary for IT Teams
Product: Microsoft Purview Data Governance, Data Quality
Threat Level: Critical, CVSS 10.0
Action Required: Review the Microsoft advisory immediately, confirm the official remediation has been applied to the service, and validate the remediation state through your standard cloud security process.
Reference
Need Help?
Secure ISS can help your organisation assess exposure, validate remediation and strengthen Microsoft Purview security controls. Contact the Secure ISS SOC team on 1300 769 460 or email us for assistance.

