PT-2026-39578 · Apache Airflow · Apache Airflow Providers Elasticsearch

·

CVE-2026-41018

·

Published

2026-05-11

·

Updated

2026-07-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-elasticsearch versions prior to 6.5.3
Description The Elasticsearch logging provider writes the full host URL into task logs when configured with a host URL that embeds credentials. This allows any user with task-log read permissions to harvest the backend credentials.
Recommendations Upgrade to version 6.5.3 or later. Configure backend credentials via a secret backend instead of embedding them in the host URL.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AZ09261
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-WQ85001
CVE-2026-41018
ECHO-AB2F-D44E-AB00
GHSA-G3JR-4JRM-JVQV
PYSEC-2026-22

Affected Products

Apache Airflow Providers Elasticsearch