CVE-2026-68969Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those secrets verbatim, and the Connection `extra` copy is stored unencrypted in the log while the connection table encrypts it. The Airflow UI's *Import Variables* action posts to this endpoint, so an ordinary operator import wrote every secret in the file to the log. This is a different code path from CVE-2026-50204: that fix shipped in 3.3.0 and covers the single-entity endpoints only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-12: 2Technical Details · 2026-08-12: 208-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-68969 Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2… https://www.cve.org/CVERecord?id=CVE-2026-68969 ----- Traducción: CVE-2026-68969 Apa… http://infoflow.cloud`

    Post summary

    The sentence announces CVE‑2026‑68969 in Apache Airflow, noting that the platform logs sensitive variable and connection data in plaintext when accessed through bulk endpoints, without any mention of PoC, explosion, patch or active exploitation.

    0000030
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-68969 Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2… https://www.cve.org/CVERecord?id=CVE-2026-68969

    Post summary

    Apache Airflow logs sensitive variable and connection information in cleartext through its bulk API endpoints, exposing data via audit logs.

    000001.3K
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more