Bypass Vulnerability in Akeyless Secrets Backend for Apache Airflow
CVE-2026-86465

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-86465?

The Akeyless provider for Apache Airflow contains a vulnerability that allows a user-scoped within one team to access secrets from other teams through the Akeyless secrets backend. This occurs when a Dag author supplies a Variable key with a path separator, thereby bypassing the intended team-scope guard. As a result, the backend may resolve a secret that belongs to a different team in a multi-team deployment scenario, exposing sensitive information. This vulnerability is specifically relevant to users of the Akeyless secrets backend with multi-team configurations and is not a concern for single-team deployments, where such cross-team access is not applicable. Users are strongly advised to upgrade to version 0.3.1 or later to mitigate this risk.

Affected Version(s)

Apache Airflow Akeyless provider 0 < 0.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ReturnZero
Jarek Potiuk
.