Multi-Team Namespace Exposure in Apache Airflow's Azure Provider
CVE-2026-68870

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-68870?

In Apache Airflow's Microsoft Azure provider, a vulnerability allows users in a multi-team environment to access secrets belonging to other teams. This occurs when a team-scoped connection or variable id is resolved through an incorrect fallback mechanism, enabling unauthorized access to sensitive credentials by simply using an id that references another team's namespace. To mitigate this risk, it is essential for users to upgrade to version 14.1.0 or later of the apache-airflow-providers-microsoft-azure package, which restricts this behavior and ensures team secrets remain protected.

Affected Version(s)

Apache Airflow Microsoft Azure provider 0 < 14.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Airflow security team
Jarek Potiuk
.