No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow Google Provider |
|
| Vendors & Products |
Apache
Apache airflow Google Provider |
Wed, 12 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Wed, 12 Aug 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name. | |
| Title | Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables | |
| Weaknesses | CWE-1220 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-12T17:20:22.433Z
Reserved: 2026-07-31T19:38:02.067Z
Link: CVE-2026-68868
Updated: 2026-08-12T17:20:22.433Z
Status : Awaiting Analysis
Published: 2026-08-12T11:17:10.063
Modified: 2026-08-12T20:50:58.370
Link: CVE-2026-68868
No data.
OpenCVE Enrichment
Updated: 2026-08-12T18:30:06Z