Cleartext Exposure in Apache Airflow Variable and Connection Audit Logs
CVE-2026-68969
Currently unrated
What is CVE-2026-68969?
Apache Airflow has a vulnerability where sensitive information, such as variable values and connection details, is logged in cleartext when submitted through its bulk API endpoints. Specifically, the lack of proper masking allows any authenticated user with access to the audit logs to retrieve confidential information verbatim. This exposure occurs because the logging mechanism only masks top-level request fields, leaving nested entities unprotected. Consequently, users are advised to upgrade to Apache Airflow version 3.3.1 or later to mitigate this security risk.
Affected Version(s)
Apache Airflow 0 < 3.3.1