Improper Access Control in Apache Airflow's Yandex Provider
CVE-2026-68871

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-68871?

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider contains a serious flaw that allows attackers to resolve secrets scoped to specific teams through incorrect namespace resolution. In multi-team deployments, a user from one team may exploit this issue to access the credentials of another team's resources merely by supplying a specific ID indicating that team's namespace. This vulnerability arises in environments where multi-team mode is enabled, posing significant security risks if left unaddressed. Users are recommended to upgrade to apache-airflow-providers-yandex version 4.5.1 or later to mitigate this risk.

Affected Version(s)

Apache Airflow Yandex provider 0 < 4.5.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Airflow security team
Jarek Potiuk
.