Executive brief
Azure Data Factory is a cloud-based data integration service used to orchestrate and automate data pipelines. A server-side request forgery (SSRF) vulnerability allows an unauthorized attacker to make requests from the service to internal or external systems, potentially exposing sensitive data, accessing internal resources, or facilitating further attacks against the organization's infrastructure.
Technical details
This vulnerability is a server-side request forgery (SSRF) in Azure Data Factory that enables an unauthenticated or unauthorized attacker to forge requests on behalf of the service. The root cause stems from insufficient validation of URLs or endpoints processed by the service, allowing an attacker to direct requests to internal resources, cloud metadata endpoints, or external systems. The attack vector is network-based; no user interaction or additional authentication is required. An attacker can exploit this to disclose sensitive information, access internal APIs, or enumerate the internal network topology. Patches are available through Microsoft's standard update mechanisms.
Affected products
- Microsoft Azure Data Factory
Timeline
- 2026-08-20: disclosed