AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-48892

MEDIUM · CVSS 6.5 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The Config API in Apache Airflow is vulnerable, allowing authenticated users with Config read permissions to access unredacted plaintext secrets-backend credentials due to improper handling of environment variable overrides. This exposure could lead to unauthorized access to sensitive information, such as Vault role IDs and secret IDs. Organizations using Apache Airflow, particularly those leveraging per-key environment overrides for secrets management, should prioritize upgrading to version 3.3.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48892
Severity
MEDIUM
CVSS
6.5
EPSS
0.41%
Apache

Original NVD Description

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API output. Affects deployments that configure secrets backends via per-key environment overrides. Users are advised to upgrade to `apache-airflow` 3.3.0 or later.

Related CVEs

Other vulnerabilities affecting the same vendor(s)