Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
The bug consists of improper access control (CWE-284) in Azure Databricks, meaning that permission verification mechanisms are not enforced properly. A remote attacker, without possessing any credentials and without requiring user interaction, can send specially crafted network requests and obtain a higher privilege level than originally granted. The network attack vector with low complexity (AC:L) makes the exploit relatively easy to perform.
An attacker can gain unauthorized privilege escalation, potentially leading to complete compromise of confidentiality, integrity, and availability of the Azure Databricks environment, including access to processed data and computing resources.
Apply patches available from the manufacturer according to references — details available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53763
Microsoft Purview Data Governance / Azure Databricks — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMicrosoft Purview Data Governance
APPMicrosoftall versions
Related vulnerabilities
Krytyczny SSRF w Microsoft Data Quality umożliwiający eskalację uprawnień
Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów