Skip to main content
cancel
Showing results for 
Search instead for 
Did you mean: 

The Fabric community is now in read-only for platform upgrade. Learn more

Reply
InsightCanvas
New Member

libcurl vulnerabilities

Our vulnerability scanner has identified several vulnerabilities affecting the bundled libcurl.dll component included with various ODBC drivers in Microsoft Power BI Desktop. The reported vulnerabilities include CVE-2026-8924, CVE-2026-8286, CVE-2026-34478, along with several others.

Could you please confirm whether Microsoft is planning to update the bundled libcurl component to address these vulnerabilities? If so, is there an estimated timeline (ETA) for when an updated version of Power BI Desktop or the affected ODBC drivers will be released?
Plugin Output

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Hive ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.44.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Quickbooks ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Spark ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\New\DocumentDB\LibCurl64.DllA\libcurl.dll
Installed version: 8.12.1.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.84.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba DocumentDB ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Hive ODBC Driver\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Impala ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

 

Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Spark ODBC Driver\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component

1 ACCEPTED SOLUTION
rajendraongole1
Super User
Super User

Hi @InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.

 

1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.

 

https://community.fabric.microsoft.com/t5/Fabric-Updates-Blog/On-premises-data-gateway-June-2026-rel...

 

Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.

 

Hope this helps.





Did I answer your question? Mark my post as a solution!

Proud to be a Super User!





View solution in original post

2 REPLIES 2
v-aatheeque
Community Support
Community Support

Hi @InsightCanvas 

Following up to confirm if the earlier responses addressed your query. If not, please share your questions and we’ll assist further.

rajendraongole1
Super User
Super User

Hi @InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.

 

1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.

 

https://community.fabric.microsoft.com/t5/Fabric-Updates-Blog/On-premises-data-gateway-June-2026-rel...

 

Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.

 

Hope this helps.





Did I answer your question? Mark my post as a solution!

Proud to be a Super User!





Helpful resources

Announcements
FabCon and SQLCon Barcelona 2026

FabCon & SQLCon – Barcelona 2026

Join us in Barcelona for FabCon and SQLCon, the Fabric, Power BI, SQL, and AI community event. Save €200 with code FABCMTY200.

Power BI DataViz World Championships carousel

Power BI DataViz World Championships - June 2026

A new Power BI DataViz World Championship is coming this June! Don't miss out on submitting your entry.