Junglewise Threat Intelligence

CVE-2026-33107: Microsoft Azure Databricks SSRF privilege escalation

CVE-2026-33107 · Severity: critical · CVSS 10 · Published 2026-04-03

Vendors: Microsoft.

Executive brief

Azure Databricks, a cloud-based data analytics platform, is affected by a critical security vulnerability that allows unauthorized users to gain elevated permissions. An attacker could exploit this flaw over the internet to bypass security controls and potentially access sensitive data or take control of the analytics environment. This poses a significant risk to data confidentiality and the integrity of business operations hosted on the platform.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Azure Databricks (CWE-918). The flaw allows an unauthenticated, remote attacker to send specially crafted network requests from the server, which can be leveraged to bypass authorization checks and achieve privilege escalation. According to the CVSS 3.1 score of 10.0, the vulnerability has a 'Changed' scope, suggesting the attacker can impact components beyond the Databricks environment itself, such as underlying cloud metadata services. Microsoft has categorized this as an exclusively hosted service vulnerability, and users should refer to the MSRC update guide for mitigation status.

Affected products

  • Microsoft Azure Databricks All versions

Timeline

  • 2026-04-02: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-04-03: advisory: NVD publication date

References