Forum Discussion

InsightCanvas's avatar
InsightCanvas
New Member
22 days ago
Solved

libcurl vulnerabilities

Our vulnerability scanner has identified several vulnerabilities affecting the bundled libcurl.dll component included with various ODBC drivers in Microsoft Power BI Desktop. The reported vulnerabilities include CVE-2026-8924, CVE-2026-8286, CVE-2026-34478, along with several others.

Could you please confirm whether Microsoft is planning to update the bundled libcurl component to address these vulnerabilities? If so, is there an estimated timeline (ETA) for when an updated version of Power BI Desktop or the affected ODBC drivers will be released?
Plugin Output

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Hive ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.44.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Quickbooks ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Spark ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\New\DocumentDB\LibCurl64.DllA\libcurl.dll
Installed version: 8.12.1.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.84.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba DocumentDB ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Hive ODBC Driver\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Impala ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Spark ODBC Driver\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

  • Hi InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.

     

    1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
    2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
    3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.

     

    https://community.fabric.microsoft.com/t5/Fabric-Updates-Blog/On-premises-data-gateway-June-2026-release/bc-p/5251347

     

    Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.

     

    Hope this helps.

2 Replies

  • Hi InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.

     

    1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
    2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
    3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.

     

    https://community.fabric.microsoft.com/t5/Fabric-Updates-Blog/On-premises-data-gateway-June-2026-release/bc-p/5251347

     

    Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.

     

    Hope this helps.

  • v-aatheeque's avatar
    v-aatheeque
    Community Support

    Hi InsightCanvas 

    Following up to confirm if the earlier responses addressed your query. If not, please share your questions and we’ll assist further.