What is CVE-2026-68871?
This CVE describes a vulnerability in the Yandex Lockbox secrets backend of Apache Airflow's Yandex provider, where team-scoped lookups could fall back to team-agnostic resolution in multi-team deployments. An attacker in one team could potentially access secrets belonging to another team. Affected users should immediately upgrade the Yandex provider or disable multi-team mode.
Azərbaycanca: Bu CVE Apache Airflow-un Yandex Lockbox secrets backend-ində çox-komandalı rejimdə icazə yanlışlığına səbəb olan zəiflikdir. Bir komandanın istifadəçisi, komandasına aid olmayan digər komandanın məxfi məlumatlarını (Connection/Variable) əldə edə bilər. Təsirə məruz qalan təşkilatlar dərhal Yandex provider-ini ən son versiyaya yeniləməli və ya çox-komandalı rejimi deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Apache
FAQ2
Which component of Apache Airflow is affected by CVE-2026-68871?
This vulnerability was discovered in the Yandex Lockbox secrets backend of Apache Airflow.
What can an attacker gain by exploiting this vulnerability?
An attacker can potentially access secrets such as Connection and Variable data belonging to another team.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.