Environment Variable Misconfiguration in Apache Airflow from Apache
CVE-2026-68076

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68076?

A security issue in Apache Airflow allows authenticated users from one team to access the connections and variables of another team due to improper checks in the environment-variable secrets backend. Specifically, the restriction mechanism fails when the team scope is not specified, and it inadequately handles team names with underscores. This flaw enables unauthorized access, allowing users to authenticate with another team's credentials while leveraging an unevaluated global variable. The exploitation requires specific configurations and knowledge of the system setup. Users are recommended to upgrade to Apache Airflow version 3.3.1 or higher to mitigate this vulnerability.

Affected Version(s)

Apache Airflow 0 < 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
Jarek Potiuk
.