CVE-2026-33107Disclosure(microsoft / azure_databricks)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_databricks systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_databricks

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-04-03); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
azure_databricks

1 version affected across 1 product

Deep dive

Activity timeline12 mentions / 6d
01345Mentions · 2026-04-02: 1Mentions · 2026-04-03: 5Mentions · 2026-04-07: 3Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Mentions · 2026-04-24: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 4Technical Details · 2026-04-07: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-24: 104-0204-0304-0704-1004-1304-24
Signal classification3 categories
Disclosure
758.3%
Patch
325.0%
General
216.7%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-021
Disclosure1
2026-04-035
Disclosure4General1
2026-04-073
General1Patch2
2026-04-101
Disclosure1
2026-04-131
Disclosure1
2026-04-241
Patch1
Full discourse12 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    ☁️ CVE-2026-33107: Azure Databricks contains a pre‑auth server‑side request forgery issue that allows a remote attacker to pivot through the service and escalate privileges in the Azure environment (CVSS 10.0, Critical). Cloud‑side fixes are live, but you should still review Databricks networking, identity paths, and logs for abuse. #Azure #Databricks #CloudSecurity #SSRF #CVE202633107 #infosec Source: https://www.cve.org/CVERecord?id=CVE-2026-33107

    Post summary

    Azure Databricks is affected by a critical pre‑authentication SSRF that can lead to privilege escalation; Microsoft has released cloud‑side fixes and advises reviewing networking, identity paths, and logs for abuse.

    1003068
    1.7K followersView on X
  • Orizon@OrizonCyber
    Disclosure

    Azure Databricks just handed attackers the keys to the kingdom. SSRF → privilege escalation → game over. CVE-2026-33107 sitting at a perfect 10.0 CVSS score. How many orgs are checking their Databricks configs right now? #infosec #CVE

    Post summary

    The tweet highlights a newly disclosed Azure Databricks vulnerability (CVE‑2026‑33107) that escalates privileges via SSRF, scoring a maximum CVSS of 10.0, and urges organizations to review their configurations.

    1000047
    22 followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    ask your AI: "check if my organization uses Azure Databricks and what version we're running — this is a Microsoft-hosted service, so check our Azure portal for Databricks workspace instances" then: "check the Microsoft security advisory for CVE-2026-33107 and apply any available patches to our Azure Databricks workspaces. also review our Databricks network configuration and access policies"

    Post summary

    The message advises reviewing Microsoft’s advisory for CVE-2026-33107, applying any available patches to Azure Databricks workspaces, and reviewing network configuration and access policies.

    1000073
    1 followersView on X
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-33107 · NIST 10.0/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33107

    Post summary

    The entry only references CVE-2026-33107 with a high NIST score and a link to the NVD page, offering no further detail or context.

    1000024
    1 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-33107: Azure Databricks SSRF Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04bmM9q0

    Post summary

    The text announces an Azure Databricks SSRF vulnerability and references a response guide, but provides no evidence of exploit code, active exploitation, or explicit patch information.

    0000066
    28 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Microsoft released Security Update to address an Elevation of Privilege Vulnerability in Microsoft Azure Databricks. #CVE-2026-33107 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33107

    Post summary

    Microsoft issued a security update patching CVE-2026-33107, an elevation‑of‑privilege flaw in Azure Databricks; no PoC, exploit, or active exploitation details are shared.

    0000097
    8.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33107 Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-33107

    Post summary

    The post announces CVE-2026-33107, a new SSRF vulnerability in Azure Databricks that could lead to privilege escalation, without providing any PoC, exploit code, or patch information.

    00000129
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33107 📊 Severity: 10.0 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33107 #CVE-2026-33107 #CVE #Critical #CyberSecurity #InfoSec https://t.co/4r0TzMTONn

    Post summary

    The tweet announces the existence of CVE-2026-33107 as a critical vulnerability (score 10.0), but offers no further technical details, exploit evidence, or patch information.

    0000046
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33107 - Azure Databricks Elevation of Privilege Vulnerability Intel Report: https://ift.tt/fq1J6rP

    Post summary

    A brief alert is issued for CVE‑2026‑33107, identifying it as an elevation‑of‑privilege flaw in Azure Databricks and linking to an Intel Report, but no detailed technical data, exploit code, or mitigation advice is provided.

    0000081
    282 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33107 - Critical Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-33107/ https://t.co/le62Sf8Z51

    Post summary

    Azure Databricks hosts a critical SSRF vulnerability (CVE‑2026‑33107) that could let an unauthenticated attacker raise privileges across the network; no proof of concept, exploit, or patch is referenced in the text.

    0000068
    160 followersView on X
  • dbugs@ptdbugs
    Disclosure

    Azure Databricks Elevation of Privilege Vulnerability CVE: CVE-2026-33107 PT ID: PT-2026-29907 Vendor: Microsoft Product: Azure Databricks CVSS: 10.0 Credits: n/a Description: Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-33107 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33107 #dbugs_vuln

    Post summary

    The text announces the discovery of CVE-2026-33107 in Azure Databricks, describing an SSRF‑based privilege escalation with a CVSS score of 10.0, and cites vendor advisory references for a patch, but provides no proof of exploitation or tool.

    00000125
    768 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33107: CRITICAL] Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.#cve,CVE-2026-33107,#cybersecurity https://cvefind.com/CVE-2026-33107

    Post summary

    The tweet announces a critical SSRF vulnerability (CVE‑2026‑33107) in Azure Databricks that enables privilege escalation over a network, with no PoC, exploit code, or patch discussion.

    0000071
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_databricks---

Explore more