Environment Variable Misconfiguration in Apache Airflow from Apache
CVE-2026-68076
Currently unrated
What is CVE-2026-68076?
A security issue in Apache Airflow allows authenticated users from one team to access the connections and variables of another team due to improper checks in the environment-variable secrets backend. Specifically, the restriction mechanism fails when the team scope is not specified, and it inadequately handles team names with underscores. This flaw enables unauthorized access, allowing users to authenticate with another team's credentials while leveraging an unevaluated global variable. The exploitation requires specific configurations and knowledge of the system setup. Users are recommended to upgrade to Apache Airflow version 3.3.1 or higher to mitigate this vulnerability.
Affected Version(s)
Apache Airflow 0 < 3.3.1