CVE-2026-68076: CWE-639: Authorization Bypass Through User-Controlled Key in Apache Software Foundation Apache Airflow
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In multi-team mode an authenticated user of one team could therefore have `POST /api/v2/connections/test` resolve another team's Connection and authenticate outward with that team's credentials; the endpoint uses the credentials rather than returning them. Exploitation requires `[core] multi_team` enabled, `[core] test_connection` set to `Enabled` (it ships `Disabled`), team-scoped secrets provisioned as environment variables in the API-server process, and knowledge of the encoded identifier. Redirecting the test at an attacker-controlled host is separately blocked. Users are advised to upgrade to apache-airflow 3.3.1 or later.
AI Analysis
Technical Summary
The vulnerability in Apache Airflow's environment-variable secrets backend arises from improper authorization checks when resolving team-scoped Connections or Variables. The guard designed to restrict access to the correct team scope only operates when no team scope is supplied and fails to match team names containing underscores, which are valid. Consequently, the lookup falls back to an unconditional global read of environment variables, allowing an authenticated user in multi-team mode to access another team's Connection credentials via the POST /api/v2/connections/test endpoint. This endpoint uses the credentials for authentication outward rather than returning them. Exploitation requires multi-team mode enabled, test_connection set to Enabled (not the default), team-scoped secrets provisioned as environment variables, and knowledge of the encoded identifier. Redirecting the test to an attacker-controlled host is blocked separately. The issue is addressed in Apache Airflow version 3.3.1 and later.
Potential Impact
An authenticated user in one team can bypass authorization controls to access and use another team's Connection credentials in multi-team mode. This could lead to unauthorized outbound authentication using another team's credentials, potentially compromising confidentiality and integrity of team-specific resources. The vulnerability requires specific configuration and knowledge, limiting its exposure to certain deployments.
Mitigation Recommendations
Users should upgrade to Apache Airflow version 3.3.1 or later, where this issue is fixed. Until then, ensure that multi-team mode is disabled or that test_connection remains set to Disabled (the default). Additionally, avoid provisioning team-scoped secrets as environment variables in the API-server process if possible. Patch status is not explicitly confirmed in the advisory, but the vendor advises upgrading to 3.3.1 or later for remediation.
CVE-2026-68076: CWE-639: Authorization Bypass Through User-Controlled Key in Apache Software Foundation Apache Airflow
Description
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In multi-team mode an authenticated user of one team could therefore have `POST /api/v2/connections/test` resolve another team's Connection and authenticate outward with that team's credentials; the endpoint uses the credentials rather than returning them. Exploitation requires `[core] multi_team` enabled, `[core] test_connection` set to `Enabled` (it ships `Disabled`), team-scoped secrets provisioned as environment variables in the API-server process, and knowledge of the encoded identifier. Redirecting the test at an attacker-controlled host is separately blocked. Users are advised to upgrade to apache-airflow 3.3.1 or later.
CVSS v3.1
Score 5.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Apache Airflow's environment-variable secrets backend arises from improper authorization checks when resolving team-scoped Connections or Variables. The guard designed to restrict access to the correct team scope only operates when no team scope is supplied and fails to match team names containing underscores, which are valid. Consequently, the lookup falls back to an unconditional global read of environment variables, allowing an authenticated user in multi-team mode to access another team's Connection credentials via the POST /api/v2/connections/test endpoint. This endpoint uses the credentials for authentication outward rather than returning them. Exploitation requires multi-team mode enabled, test_connection set to Enabled (not the default), team-scoped secrets provisioned as environment variables, and knowledge of the encoded identifier. Redirecting the test to an attacker-controlled host is blocked separately. The issue is addressed in Apache Airflow version 3.3.1 and later.
Potential Impact
An authenticated user in one team can bypass authorization controls to access and use another team's Connection credentials in multi-team mode. This could lead to unauthorized outbound authentication using another team's credentials, potentially compromising confidentiality and integrity of team-specific resources. The vulnerability requires specific configuration and knowledge, limiting its exposure to certain deployments.
Mitigation Recommendations
Users should upgrade to Apache Airflow version 3.3.1 or later, where this issue is fixed. Until then, ensure that multi-team mode is disabled or that test_connection remains set to Disabled (the default). Additionally, avoid provisioning team-scoped secrets as environment variables in the API-server process if possible. Patch status is not explicitly confirmed in the advisory, but the vendor advises upgrading to 3.3.1 or later for remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-30T09:10:44.222Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7c944ebf8831d539c07f58
Added to database: 08/12/2026, 15:42:06 UTC
Last enriched: 08/12/2026, 16:01:11 UTC
Last updated: 08/13/2026, 02:01:20 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.