Environment Variable Misconfiguration in Apache Airflow from Apache
CVE-2026-68076

5.4MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68076?

A security issue in Apache Airflow allows authenticated users from one team to access the connections and variables of another team due to improper checks in the environment-variable secrets backend. Specifically, the restriction mechanism fails when the team scope is not specified, and it inadequately handles team names with underscores. This flaw enables unauthorized access, allowing users to authenticate with another team's credentials while leveraging an unevaluated global variable. The exploitation requires specific configurations and knowledge of the system setup. Users are recommended to upgrade to Apache Airflow version 3.3.1 or higher to mitigate this vulnerability.

Affected Version(s)

Apache Airflow 0 < 3.3.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
Jarek Potiuk
.