Skip to main content
Vulnerability Database/CVE-2026-97636

CVE-2026-97636: Apache Airflow HashiCorp Auth Bypass

CVE-2026-97636 is an authentication bypass flaw in Apache Airflow HashiCorp Vault provider affecting multi-team deployments. Attackers can access secrets from other teams using path separators in variable keys. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-97636 Overview

CVE-2026-97636 affects the apache-airflow-providers-hashicorp package used by Apache Airflow deployments. The HashiCorp Vault secrets backend contains a team-scope guard that can be bypassed through a user-controlled Variable key. In multi-team deployments, a Dag author scoped to one team can supply a key containing a path separator to resolve a secret belonging to a different team. The flaw stems from a fallback to a team-agnostic path concatenated from the unvalidated key after the team-scoped lookup misses. The Execution API Variables route accepts path-shaped keys, making the issue reachable from ordinary Dag code. The vulnerability is categorized under CWE-639: Authorization Bypass Through User-Controlled Key.

Critical Impact

A Dag author in one team can read Airflow Variables and secrets owned by another team in multi-team Vault-backed deployments, breaking tenant isolation.

Affected Products

  • Apache Airflow HashiCorp provider (apache-airflow-providers-hashicorp) versions prior to 4.8.0
  • Multi-team Apache Airflow deployments using the HashiCorp Vault secrets backend
  • Deployments exposing the Execution API Variables route to Dag authors

Discovery Timeline

  • 2026-09-24 - CVE CVE-2026-97636 published to NVD
  • 2026-09-25 - Last updated in NVD database

Technical Details for CVE-2026-97636

Vulnerability Analysis

The HashiCorp Vault secrets backend in Airflow performs a two-step lookup when a Dag requests a Variable. First, it attempts a team-scoped path that incorporates the caller's team identifier. If that lookup misses, the backend falls back to a team-agnostic path built by concatenating a base prefix with the raw Variable key. The key is not validated for path separators before concatenation. A Dag author scoped to team A can submit a key such as teamB/secret_name and have the backend resolve a secret belonging to team B. This breaks the tenant isolation model that the team-scope guard is intended to enforce.

Root Cause

The root cause is improper authorization enforced through a user-controlled key [CWE-639]. The fallback path logic trusts the caller-supplied key as an opaque identifier when it is in fact a hierarchical path. Because Vault treats slashes as path separators, injected separators change the effective lookup location. The authorization decision is bound to the team context used in the first lookup, but no equivalent check gates the second lookup.

Attack Vector

An authenticated Dag author with permission to write Dag code in a multi-team deployment supplies a path-shaped key through the Execution API Variables route. The backend fails the team-scoped resolution, then issues a second Vault read against a team-agnostic path assembled from the attacker-controlled key. The returned secret is delivered to the attacker's Dag runtime. The attack requires low privileges, no user interaction, and executes over the network. This vulnerability is in the same class as CVE-2026-86465, CVE-2026-68870, CVE-2026-68871, and CVE-2026-68872, which affect the Akeyless, Azure Key Vault, Yandex Lockbox, and Amazon secrets backends respectively.

No verified public exploit code is available. See the GitHub Pull Request #70006 and the Apache Mailing List Discussion for the fix and advisory details.

Detection Methods for CVE-2026-97636

Indicators of Compromise

  • Vault audit log entries showing reads against team-agnostic Variable paths originating from team-scoped Airflow worker tokens.
  • Variable keys submitted through the Execution API that contain /, .., or other path separators.
  • Dag code referencing Variable keys that do not match the naming convention enforced for the Dag author's team.

Detection Strategies

  • Review Vault audit logs for vault read operations where the resolved path's team segment does not match the requesting worker's team identity.
  • Correlate Airflow task logs with Vault reads to identify Variable lookups that fell through from team-scoped to team-agnostic paths.
  • Scan Dag source repositories for Variable.get() or {{ var.value.* }} references containing path separators in the key argument.

Monitoring Recommendations

  • Enable Vault audit logging for all Variable path prefixes used by Airflow and forward events to a central analytics platform.
  • Alert on any Dag parse or execution event that submits a Variable key containing /.
  • Baseline per-team Variable read volume and alert on sudden cross-team access patterns.

How to Mitigate CVE-2026-97636

Immediate Actions Required

  • Upgrade apache-airflow-providers-hashicorp to version 4.8.0 or later in all multi-team deployments.
  • Rotate any Vault-backed secrets accessible via the team-agnostic fallback path if cross-team access cannot be ruled out from audit logs.
  • Audit existing Dags for Variable keys containing path separators and remediate before upgrading.

Patch Information

The fix is included in apache-airflow-providers-hashicorp version 4.8.0. The patch validates Variable keys and removes the unsafe fallback behavior that concatenated unvalidated keys into a team-agnostic Vault path. Technical details are available in GitHub Pull Request #70006.

Workarounds

  • Restrict the HashiCorp Vault backend configuration so that the team-agnostic fallback path is not reachable, where deployment architecture permits.
  • Enforce input validation at the Dag review stage to reject Variable keys containing / or .. characters.
  • Apply Vault policies that scope worker tokens strictly to their team's path prefix, blocking cross-team reads at the Vault layer.
bash
# Upgrade the HashiCorp provider to the fixed version
pip install --upgrade "apache-airflow-providers-hashicorp>=4.8.0"

# Verify the installed version
pip show apache-airflow-providers-hashicorp | grep -i version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.