Bypass Vulnerability in Akeyless Secrets Backend for Apache Airflow
CVE-2026-86465
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-86465?
The Akeyless provider for Apache Airflow contains a vulnerability that allows a user-scoped within one team to access secrets from other teams through the Akeyless secrets backend. This occurs when a Dag author supplies a Variable key with a path separator, thereby bypassing the intended team-scope guard. As a result, the backend may resolve a secret that belongs to a different team in a multi-team deployment scenario, exposing sensitive information. This vulnerability is specifically relevant to users of the Akeyless secrets backend with multi-team configurations and is not a concern for single-team deployments, where such cross-team access is not applicable. Users are strongly advised to upgrade to version 0.3.1 or later to mitigate this risk.
Affected Version(s)
Apache Airflow Akeyless provider 0 < 0.3.1