CVE-2026-33107 is a critical server-side request forgery (SSRF) vulnerability found in Azure Databricks. This flaw, rated 10.0 CVSS, allows an unauthenticated, remote attacker to achieve privilege escalation with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available via Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating no active exploitation. Despite the lack of public exploits, the vulnerability has garnered some community discussion on social media platforms, suggesting awareness among cybersecurity professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_databricks:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.