← Vulnerability feed

Vulnerability record · CVE-2026-68868 · published 12 August 2026

CVE-2026-68868: Apache-airflow-providers-google vulnerability

Apache · Apache Airflow Providers Google

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.

6.5 CVSS 3.1 Medium EPSS 0.60% · top 53.7% CWE-1220 · CWE-1220
6.5CVSS 3.1 base score
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
16 Sep 2026Last modified by NVD

Description

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-68868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-25691Apache-airflow-providers-google improper input validation vulnerabilityImproper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10…EPSS 1.6%8.1CVE-2026-49297Apache-airflow-providers-google path traversal vulnerabilityApache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket …EPSS 0.99%8.1CVE-2026-45361Apache-airflow-providers-google vulnerabilityApache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worke…EPSS 0.80%7.5CVE-2023-25692Apache-airflow-providers-google improper input validation vulnerabilityImproper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10…EPSS 1.8%7.8CVE-2026-56155Microsoft AD FS access control flaw allows local privilege elevationActive Directory Federation Services (AD FS) on multiple Windows client and server versions has insufficient granularity in its access control, letti…KEVEPSS 0.35%analysed7.8CVE-2026-33825Microsoft Defender Antimalware Platform access control flaw allows local privilege escalationMicrosoft Defender Antimalware Platform has insufficient granularity of access control (CWE-1220), letting an authorized local attacker elevate privi…KEVEPSS 0.40%analysed9.8CVE-2025-31201Apple OS Pointer Authentication bypass via arbitrary read/writeApple removed vulnerable code that allowed an attacker holding arbitrary read and write capability to bypass Pointer Authentication across iOS, iPadO…KEVEPSS 14%analysed

Source: NIST National Vulnerability Database (record CVE-2026-68868), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.