External risk intelligence

Azure Databricks SSRF Vulnerability Allows Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-33107

Azure Databricks is a cloud-based data analytics platform. While it involves network-reachable services, it typically operates within restricted, authenticated, or VPC-isolated environments rather than serving as a public-facing web endpoint. Public exposure is possible depending on specific workspace configurations, but it is not a characteristic of its standard, default deployment.

Server-Side Request Forgery

Microsoft Azure Databricks

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Azure Databricks, a platform used for data analytics. This issue, classified as Server-Side Request Forgery, could allow an attacker to gain elevated privileges without needing prior authorization. The main concern is to confirm if our specific Azure Databricks environments are relevant and potentially exposed.

  • Attackers could gain extra control.
  • Understand how data analytics platforms are secured.
  • Verify our Azure Databricks exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a malicious request over the network to Azure Databricks. Because the vulnerability exists in a server-side component that handles requests, the attacker does not need any prior authentication or special user interface interaction to trigger it. Successful exploitation could allow the attacker to gain elevated privileges within the Azure Databricks environment.

  • No authentication required.
  • Server-side request forgery.
  • Privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

Server-side request forgery in Azure Databricks could allow an attacker to elevate privileges by making unauthorized requests on behalf of the service. This could affect access to internal resources when the service is configured to allow external network access.

  • Internal network access and service configurations.
  • Unauthorized network requests initiated by the service.
  • Potential for privilege escalation and unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Server-Side Request Forgery (SSRF) vulnerability in Azure Databricks impacts privilege escalation and requires immediate attention from platform and security teams. The first step is to identify all Azure Databricks instances, determine their network exposure and business criticality, and pinpoint the accountable owner for each. Subsequently, a risk-based remediation plan should be developed, potentially involving coordination with Microsoft and vendor-management teams.

  • Platform and Security teams own the issue.
  • Verify network exposure and asset criticality first.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Azure Databricks?

Azure Databricks is a cloud-based platform designed for data analytics and large-scale data processing. It provides a collaborative workspace where teams can run complex data engineering, machine learning, and analytics workflows, usually operating within cloud environments to handle significant data tasks.

How does this SSRF vulnerability work?

This flaw is classified as CWE-918, or Server-Side Request Forgery. It occurs when an application is tricked into sending unauthorized requests to unintended locations. In CVE-2026-33107, an attacker leverages this behavior to force the service to perform actions on their behalf, ultimately allowing them to elevate their privileges within the platform.

Do I need to be authenticated to trigger CVE-2026-33107?

No, prior authentication is not required to trigger this vulnerability. Because the flaw exists in a server-side component that processes incoming network requests, an attacker can initiate the attack without needing a user account or any special interaction with the platform's interface.

Is my instance relevant to this threat?

Halo Surface Signal notes that while Azure Databricks typically runs in isolated or authenticated environments, your specific risk depends on workspace configuration. If your deployment is reachable via the public internet rather than restricted to a private or VPC-isolated network, it is more likely to be relevant to this network-based vulnerability.

How should I respond to this advisory?

Begin by creating a comprehensive inventory of all Azure Databricks instances in your environment. For each instance, confirm who owns it, how it is connected to the network, and how critical it is to your business operations. This information will help you prioritize your response and coordinate effectively with your platform security team.

References