CVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
Apache Airflow HashiCorp provider flaw lets a team-scoped DAG author read another team's Vault secret.
Apache disclosed CVE-2026-97636, rated moderate, in the Apache Airflow HashiCorp provider. Versions 4.6.0 before 4.8.0 let a DAG author scoped to one team supply a Variable key containing a path separator so the Vault secrets backend resolves a secret owned by another team. The issue affects multi-team deployments that use the Vault secrets backend. Apache fixed the guard bypass in provider 4.8.0.
48