CVE-2026-32794 is a medium-severity Improper Certificate Validation vulnerability (CWE-295) affecting Apache Airflow Provider for Databricks versions 1.10.0 through 1.11.x. This flaw, with a CVSS score of 4.8, allows a remote attacker to perform a Man-in-the-Middle (MitM) attack with high attack complexity due to the provider's failure to validate certificates for Databricks backend connections. Such an attack could lead to intercepted traffic manipulation or credential exfiltration without notice. There is no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability. Users are strongly advised to upgrade to version 1.12.0 or later to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.0, < 1.12.0CPE matchmatch criteria | cpe:2.3:a:apache:airflow_providers_databricks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
Mar 31, 2026CVE-2026-32794: Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange
Mar 30, 2026