PT-2026-71048 · Apache Airflow · Apache Airflow Google Provider

·

CVE-2026-68868

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-google versions prior to 22.3.0
Description The Google Cloud Secret Manager secrets backend in the Google provider fails to apply the team scope when resolving Connections and Variables. Although the team name variable is accepted by the backend, it is dropped at the internal call boundary, causing lookups to resolve against team-agnostic secret names. In deployments using multi-team mode, this allows a task or DAG belonging to one team to resolve and obtain the full credentials of a Connection or Variable belonging to another team.
Recommendations Upgrade to apache-airflow-providers-google version 22.3.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68868
PYSEC-2026-3714

Affected Products

Apache Airflow Google Provider