Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-68970

 

Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-68970

Published: August 24, 2026


Vulnerability identifier: #VU144881
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68970
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper masking of sensitive data in Task SDK Variable handling when rendering task logs or the Rendered Templates UI for Variables whose JSON value is a top-level list. A remote user can read a task log or rendered template that references such a Variable to disclose sensitive information.

No special configuration is required, and only top-level list-shaped JSON Variable values are exposed unmasked.


Affected software

Apache Airflow

How to mitigate CVE-2026-68970

Install security update from vendor's website.

Apache Airflow - update to 3.3.1

External References

Related Security Bulletins