CVE-2026-32794

CVE-2026-32794: Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange

Vendor Apache Software Foundation
Product Apache Airflow Provider for Databricks
Weakness CWE-295
Published March 30, 2026
Last update March 31, 2026

CVSS base score

What the vulnerability does

Description

Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulated or credentials exfiltrated w/o notice. This issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

Key dates

Disclosure timeline

March 30, 2026 CVE published
March 31, 2026 Record updated