Data Leak in Apache Airflow's Amazon Provider Plugins
CVE-2026-68872
Currently unrated
What is CVE-2026-68872?
A vulnerability exists in Apache Airflow's Amazon provider plugins that could allow members of one team to access sensitive credentials belonging to another team in a multi-team deployment. This occurs when a team-scoped Connection or Variable ID is resolved through a team-agnostic method, which can inadvertently expose secrets. To mitigate this risk, users should ensure they upgrade to version 9.34.0 or later of the apache-airflow-providers-amazon package, which addresses this issue by preventing unauthorized access through improper id resolution methods.
Affected Version(s)
Apache Airflow Amazon provider 0 < 9.34.0