What is CVE-2026-68870?
CVE-2026-68870 was identified in the Azure Key Vault secrets backend of Apache Airflow's Microsoft Azure provider. In multi-team mode, when a team-scoped lookup misses, the backend may fall back to a team-agnostic lookup, allowing a caller in one team to resolve a Connection or Variable id belonging to another team. Users should upgrade to the latest patched version of the provider to mitigate this issue.
Azərbaycanca: CVE-2026-68870, Apache Airflow-in Microsoft Azure provayderində Azərbaycan Key Vault "secrets" backendində tapılıb. Multi-team rejimdə, bir komandadan olan istifadəçi, team-scoped lookup uğursuz olduqda, başqa komandaya aid Connection və ya Variable identifikatorunu team-agnostic lookup vasitəsilə əldə edə bilər. Bu boşluqdan qorunmaq üçün provayderi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Apache
FAQ2
Where was CVE-2026-68870 discovered?
CVE-2026-68870 was identified in the Azure Key Vault secrets backend of Apache Airflow's Microsoft Azure provider.
What privacy issue can this vulnerability cause in multi-team mode?
When a team-scoped lookup misses, the backend may fall back to a team-agnostic lookup, allowing a caller in one team to resolve a Connection or Variable id belonging to another team.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.