HashiCorp Vault Secrets Backend Vulnerability in Apache Airflow
CVE-2026-97636

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97636?

In Apache Airflow, a vulnerability exists within the HashiCorp Vault secrets backend where the team-scope guard can be bypassed through a user-controlled key. This is particularly concerning for multi-team deployments, allowing a Dag author from one team to influence the resolution of a secret intended for a different team. By providing a Variable key with a path separator, malicious users can manipulate the backend lookup sequence, resulting in unauthorized access to sensitive information. To mitigate this issue, users should upgrade to version 4.8.0 or later of the apache-airflow-providers-hashicorp.

Affected Version(s)

Apache Airflow HashiCorp provider 4.6.0 < 4.8.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ReturnZero
Bas Harenslak
.