Cleartext Exposure in Apache Airflow Variable and Connection Audit Logs
CVE-2026-68969

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68969?

Apache Airflow has a vulnerability where sensitive information, such as variable values and connection details, is logged in cleartext when submitted through its bulk API endpoints. Specifically, the lack of proper masking allows any authenticated user with access to the audit logs to retrieve confidential information verbatim. This exposure occurs because the logging mechanism only masks top-level request fields, leaving nested entities unprotected. Consequently, users are advised to upgrade to Apache Airflow version 3.3.1 or later to mitigate this security risk.

Affected Version(s)

Apache Airflow 0 < 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jarek Potiuk
.