Junglewise Threat Intelligence

CVE-2026-57106: Microsoft Purview Data Governance SSRF in Data Quality

CVE-2026-57106 · Severity: critical · CVSS 10 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

A critical security vulnerability has been identified in Microsoft Purview Data Governance, a service used by organizations to manage and improve the quality of their data assets. An unauthorized attacker could exploit this flaw to gain elevated administrative privileges over the network. This could lead to a total compromise of the data governance environment, allowing unauthorized access to sensitive information or disruption of data management operations.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Data Quality component of Microsoft Purview Data Governance. The flaw (CWE-918) allows an unauthenticated attacker to send specially crafted network requests from the server, which can be leveraged to bypass security boundaries and elevate privileges. Given the CVSS score of 10.0 and the 'Changed' scope (S:C), the exploit likely allows the attacker to pivot from the vulnerable service to other internal resources or cloud metadata services to obtain high-level administrative credentials. The vulnerability is exploitable over the network without user interaction. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly to the cloud environment.

Affected products

  • Microsoft Purview Data Governance Data Quality component

Timeline

  • 2026-07-24: disclosed: Initial publication by Microsoft and NVD.

References