What is CVE-2026-68868?
CVE-2026-68868 involves the Google Cloud Secret Manager backend in Apache Airflow's Google provider. The vulnerability occurs because the `team_name` parameter is accepted but dropped during internal calls, causing all Connections and Variables lookups to resolve without team scope. Affected users should upgrade their provider and review team-based access controls.
Azərbaycanca: CVE-2026-68868 Apache Airflow-un Google təminatçısında Google Cloud Secret Manager arxa hissəsi ilə bağlıdır. Bu zəiflik səbəbindən, 'team_name' parametri qəbul edilsə də, daxili çağırış zamanı nəzərə alınmır, nəticədə Connections və Variables sorğuları komanda əhatəsi olmadan həll edilir. İstifadəçilər öz təminatçı versiyalarını yeniləməli və komanda əsaslı giriş nəzarətlərini nəzərdən keçirməlidir.
FAQ2
What is the root cause of CVE-2026-68868 in the Apache Airflow Google provider?
The vulnerability is caused by the `team_name` parameter being accepted but dropped during internal calls, resulting in Connections and Variables lookups resolving without team scope.
What should users affected by CVE-2026-68868 do?
Affected users should upgrade their provider and review team-based access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.