Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-68969

 

Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-68969

Published: August 24, 2026


Vulnerability identifier: #VU144880
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68969
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of sensitive information in the bulk Variable and Connection audit logging logic when processing bulk update requests to the variables and connections API endpoints. A remote user can submit a bulk request and read the resulting audit log entries to disclose sensitive information.

The issue affects secret values in Variable entries and Connection extra contents, including secrets submitted through the UI import action that uses the bulk variables endpoint.


Affected software

Apache Airflow

How to mitigate CVE-2026-68969

Install security update from vendor's website.

Apache Airflow - update to 3.3.1

External References

Related Security Bulletins