🟠 High | Source: Microsoft Security Response Center
CVE-2026-57106 is a server-side request forgery (SSRF) vulnerability in Microsoft Azure Data Quality that allows an unauthenticated attacker to elevate their privileges over a network. SSRF flaws can enable attackers to make requests on behalf of the server, potentially accessing internal resources or cloud metadata endpoints. The unauthenticated nature of this exploit significantly raises the risk, as no prior access is required.
Security Architect’s Take: Review network access controls to restrict exposure of Azure Data Quality endpoints, particularly from untrusted or public networks, and apply Microsoft’s patch immediately. Audit logs for unusual outbound requests from Data Quality services that may indicate prior exploitation.
Original advisory: CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability