CVE-2026-66800: Azure Data Factory Information Disclosure Vulnerability
Published Aug 20, 2026
·Updated
Azure Data Factory Information Disclosure Vulnerability
Other sources
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
1 affected component
Microsoft Azure Data Factory
Event History
Aug 20, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is described as exploitable by an unauthorized attacker over a network. The vector indicates no privileges or user interaction are required.
2
What is the likely security impact?
The reported impact is information disclosure. The supplied vector rates confidentiality impact as high and does not identify integrity or availability impact.
3
Is there an indication that exploitation is easy or requires a special configuration?
The vector identifies low attack complexity, but the provided information does not state whether a default Azure Data Factory configuration is affected or what specific setup enables exploitation.