CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8522

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key

Apache Airflow HashiCorp provider versions 4.6.0 through 4.7.x contain a moderate severity vulnerability in the HashiCorp Vault secrets backend that allows a Directed Acyclic Graph (DAG) author to bypass team-scope isolation. An attacker can craft a variable key with path separators to access secrets belonging to other teams in a multi-team deployment.

Why it matters: Organizations running Apache Airflow with HashiCorp Vault and multiple teams face cross-team secret exposure; teams should upgrade to version 4.8.0 or later immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary