This is best Fabric, Power BI, SQL and AI community event. How do we know? The last event sold out! Save €200 with code FABCMTY200.
Register nowThe Fabric community is now in read-only for platform upgrade. Learn more
Our vulnerability scanner has identified several vulnerabilities affecting the bundled libcurl.dll component included with various ODBC drivers in Microsoft Power BI Desktop. The reported vulnerabilities include CVE-2026-8924, CVE-2026-8286, CVE-2026-34478, along with several others.
Could you please confirm whether Microsoft is planning to update the bundled libcurl component to address these vulnerabilities? If so, is there an estimated timeline (ETA) for when an updated version of Power BI Desktop or the affected ODBC drivers will be released?
Plugin Output
Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Hive ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.44.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Quickbooks ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\Microsoft Power BI Desktop\bin\ODBC Drivers\Simba Spark ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.60.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\New\DocumentDB\LibCurl64.DllA\libcurl.dll
Installed version: 8.12.1.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Google BigQuery ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 7.84.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba DocumentDB ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Hive ODBC Driver\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Impala ODBC Driver\LibCurl64.DllA\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Path: C:\Program Files\On-premises data gateway\m\ODBC Drivers\Simba Spark ODBC Driver\libcurl.dll
Installed version: 8.7.0.0
Fixed version: 8.21.0
Potential Vulnerability: Component
Solved! Go to Solution.
Hi @InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.
1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.
Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.
Hope this helps.
Proud to be a Super User! | |
Following up to confirm if the earlier responses addressed your query. If not, please share your questions and we’ll assist further.
Hi @InsightCanvas - The libcurl.dll files you're seeing are bundled with third-party Simba ODBC drivers that ship with Power BI Desktop and the On-premises Data Gateway. Vulnerability scanners often flag these based on the library version, but whether a specific CVE is exploitable depends on how the driver uses the affected functionality.
1. Open a Microsoft Support ticket if the issue requires an official security assessment or remediation timeline.
2. Monitor the monthly Power BI Desktop and On-premises Data Gateway release notes for updates to bundled drivers and security fixes.
3. Validate whether the reported CVEs are actually applicable to your deployment, as version-based scanner findings can sometimes be false positives if the vulnerable code paths are not used.
Until Microsoft publishes an official advisory or release, any timeline for updating the bundled libcurl libraries would be speculative.
Hope this helps.
Proud to be a Super User! | |
Join us in Barcelona for FabCon and SQLCon, the Fabric, Power BI, SQL, and AI community event. Save €200 with code FABCMTY200.
| User | Count |
|---|---|
| 23 | |
| 22 | |
| 14 | |
| 14 | |
| 13 |
| User | Count |
|---|---|
| 47 | |
| 39 | |
| 24 | |
| 20 | |
| 20 |