What is CVE-2026-68872?
This CVE describes a vulnerability in Apache Airflow's AWS SSM Parameter Store and Secrets Manager backends where, in multi-team mode deployments, a team-scoped lookup failure falls back to a team-agnostic lookup, potentially exposing team-scoped Connection and Variable IDs to unauthorized callers from another team. Affected users should upgrade their Apache Airflow Amazon provider packages to the latest patched version.
Azərbaycanca: Bu CVE Apache Airflow-un AWS SSM Parameter Store və Secrets Manager backendlərində çoxkomandalı rejimdə işləyən deploymentlərdə, komanda-səviyyəli lookup-un tapılmadığı zaman komandadan kənar lookup-a keçid edərək komanda-əhatəli Connection və Variable ID-lərin icazəsiz ifşa edilməsinə səbəb olan zəifliyi təsvir edir. Bu, bir komandadan olan çağırıcının digər komandaya aid həssas məlumatlara çıxış əldə etməsinə imkan verir. Təsirə məruz qalan istifadəçilər Apache Airflow provayderlərini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: AWS
FAQ2
In which backends of Apache Airflow was the CVE-2026-68872 vulnerability discovered?
This vulnerability was discovered in Apache Airflow's AWS SSM Parameter Store and Secrets Manager backends.
What type of data is exposed due to the CVE-2026-68872 vulnerability?
This vulnerability allows a caller from one team to gain unauthorized access to team-scoped Connection and Variable IDs belonging to another team.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.