Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authent…
Medium CVSS 6.5
Summary
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option n…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/apache/airflow/pull/70755 Issue Tracking
- https://lists.apache.org/thread/kykn94kjf0tntx4wywtvjowh5bzdgf38 Mailing List
- https://www.cve.org/CVERecord?id=CVE-2026-48828 Not Applicable
- https://www.cve.org/CVERecord?id=CVE-2026-48892 Not Applicable
Timeline
- nvd_ingest NVD