Information disclosure in Apache Airflow - CVE-2026-48892
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Config API when handling configuration read requests. A remote user can query the Config API to disclose sensitive information.
Only deployments that configure secrets backends via per-key environment overrides are vulnerable.