As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
Apache Airflow HashiCorp provider versions 4.6.0 through 4.7.x contain a moderate severity vulnerability in the HashiCorp Vault secrets backend that allows a Directed Acyclic Graph (DAG) author to bypass team-scope isolation. An attacker can craft a variable key with path separators to access secrets belonging to other teams in a multi-team deployment.
Why it matters: Organizations running Apache Airflow with HashiCorp Vault and multiple teams face cross-team secret exposure; teams should upgrade to version 4.8.0 or later immediately.
- Source published
- First seen by Cybersecurity Tracker