Improper access control in Apache Airflow - CVE-2026-48828
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the bulk variables api when processing bulk variable read requests for json-decodable variable values. A remote user can retrieve bulk variable data to disclose sensitive information.
Only deployments that store sensitive values in json-typed variables under secret-suffixed key names are affected.