Multi-Team Namespace Exposure in Apache Airflow's Azure Provider
CVE-2026-68870
5.3MEDIUM
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 10 August 2026
What is CVE-2026-68870?
In Apache Airflow's Microsoft Azure provider, a vulnerability allows users in a multi-team environment to access secrets belonging to other teams. This occurs when a team-scoped connection or variable id is resolved through an incorrect fallback mechanism, enabling unauthorized access to sensitive credentials by simply using an id that references another team's namespace. To mitigate this risk, it is essential for users to upgrade to version 14.1.0 or later of the apache-airflow-providers-microsoft-azure package, which restricts this behavior and ensures team secrets remain protected.
Affected Version(s)
Apache Airflow Microsoft Azure provider 0 < 14.1.0