๐Ÿ” CVE Alert

CVE-2026-86465

UNKNOWN 0.0

Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team, because the lookup path is concatenated from an unvalidated key after the team-scoped lookup misses. The Execution API Variables route accepts a path-shaped key, so this is reachable from ordinary Dag code. Affects multi-team deployments using the Akeyless secrets backend. Single-team deployments are not affected, as there is no cross-team boundary to cross. This is the same class as CVE-2026-68870, CVE-2026-68871 and CVE-2026-68872 in the Azure Key Vault, Yandex Lockbox and Amazon secrets backends. Users of apache-airflow-providers-akeyless are recommended to upgrade to version 0.3.1 or later, which fixes the issue.

CWE CWE-639
Vendor apache software foundation
Product apache airflow akeyless provider
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow akeyless provider

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow akeyless provider are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow Akeyless provider
0 < 0.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/72646 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-68870 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-68871 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-68872 lists.apache.org: https://lists.apache.org/thread/vczt5xgqjv8ot8fpp1vdq3rmnfm50w0g

Credits

ReturnZero Jarek Potiuk