Server-side Request Forgery in Azure Data Factory by Microsoft
CVE-2026-66800

8.6HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
20 August 2026

What is CVE-2026-66800?

A server-side request forgery (SSRF) vulnerability in Azure Data Factory permits unauthorized attackers to make requests that can lead to information disclosure across the network. This flaw can potentially allow attackers to exploit the system by accessing sensitive data that should remain protected. Organizations using Azure Data Factory must ensure they are aware of this vulnerability and apply recommended mitigations as advised by Microsoft.

Affected Version(s)

Azure Data Factory -

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.