Data Leak in Apache Airflow's Amazon Provider Plugins
CVE-2026-68872

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 August 2026

What is CVE-2026-68872?

A vulnerability exists in Apache Airflow's Amazon provider plugins that could allow members of one team to access sensitive credentials belonging to another team in a multi-team deployment. This occurs when a team-scoped Connection or Variable ID is resolved through a team-agnostic method, which can inadvertently expose secrets. To mitigate this risk, users should ensure they upgrade to version 9.34.0 or later of the apache-airflow-providers-amazon package, which addresses this issue by preventing unauthorized access through improper id resolution methods.

Affected Version(s)

Apache Airflow Amazon provider 0 < 9.34.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Airflow security team
Jarek Potiuk
.