๐Ÿ” CVE Alert

CVE-2026-97636

UNKNOWN 0.0

Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team, because after the team-scoped lookup misses the backend falls back to a team-agnostic path concatenated from the unvalidated key. The Execution API Variables route accepts a path-shaped key, so this is reachable from ordinary Dag code. Affects multi-team deployments using the HashiCorp Vault secrets backend. Single-team deployments are not affected, as there is no cross-team boundary to cross. This is the same class as CVE-2026-86465, CVE-2026-68870, CVE-2026-68871 and CVE-2026-68872 in the Akeyless, Azure Key Vault, Yandex Lockbox and Amazon secrets backends. Users of apache-airflow-providers-hashicorp are recommended to upgrade to version 4.8.0 or later, which fixes the issue.

CWE CWE-639
Vendor apache software foundation
Product apache airflow hashicorp provider
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow hashicorp provider

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow hashicorp provider are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow HashiCorp provider
4.6.0 < 4.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/70006 lists.apache.org: https://lists.apache.org/thread/l0fogo9dh5v07vnsxnhoh3c74othkr51 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-68870 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-68871 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-68872 cve.org: https://www.cve.org/CVERecord?id=CVE-2026-86465

Credits

ReturnZero Bas Harenslak