


Perceptive Security
SOC/SIEM Consultancy

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Published:
2 april 2026 om 22:00:00
Alert date:
3 april 2026 om 01:02:29
Source:
nvd.nist.gov
Cloud & Virtualization, Enterprise Applications
A server-side request forgery (SSRF) vulnerability has been identified in Azure Databricks that allows unauthorized attackers to elevate privileges over a network. This vulnerability enables attackers to exploit the trust relationship between the server and internal network resources. The flaw could potentially allow attackers to access internal services, bypass network security controls, and gain elevated access to cloud infrastructure components. Given the cloud-based nature of Azure Databricks and its enterprise usage, this vulnerability poses significant security risks to organizations using the platform.
Technical details
Mitigation steps:
Affected products:
Azure Databricks
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33107
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33107
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
