Improper Access Control in Apache Airflow's Yandex Provider
CVE-2026-68871

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-68871?

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider contains a serious flaw that allows attackers to resolve secrets scoped to specific teams through incorrect namespace resolution. In multi-team deployments, a user from one team may exploit this issue to access the credentials of another team's resources merely by supplying a specific ID indicating that team's namespace. This vulnerability arises in environments where multi-team mode is enabled, posing significant security risks if left unaddressed. Users are recommended to upgrade to apache-airflow-providers-yandex version 4.5.1 or later to mitigate this risk.

Affected Version(s)

Apache Airflow Yandex provider 0 < 4.5.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Airflow security team
Jarek Potiuk
.