
🟠 HIGH CVE-2026-49297 Path traversal in Apache Airflow's Google provider (apache-airflow-providers-google before 22.2.1) lets a party with write access to a source GCS bucket overwrite arbitrary files on an SFTP server or Air… https://vuln.today/cve/CVE-2026-49297 #CVE #infosec
Post summary
The post announces a newly disclosed CVE-2026-49297 involving path traversal in Apache Airflow’s Google provider that permits arbitrary file overwrite on an SFTP server, but does not provide PoC, exploit code, or mitigation information.

