Intel

AIKIDO-2026-21865

apache-airflow-providers-hashicorp is vulnerable to Authorization Bypass Through User-Controlled Key

Authorization Bypass Through User-Controlled KeyCVE-2026-97636 Published 4 days ago

65

Medium Risk

This Affects:

PYTHONapache-airflow-providers-hashicorp
4.6.0 - 4.7.2
Fixed in 4.8.0
Are you affected? Scan for Free

TL;DR

The HashiCorp Vault secrets backend's team scoped lookup uses a team agnostic {base_path}/{key} path built from the caller supplied variable or connection key when that lookup finds no value. In a multi team deployment, a Dag author scoped to one team can supply a key that matches this shared fallback path and read a secret that belongs to a different team. The Execution API Variables route accepts this path shaped key directly from ordinary Dag code, so no elevated access is required to reach it. The fix removes the team agnostic fallback and uses an explicit, ordered list of configured base paths.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run a multi team Airflow deployment with the HashiCorp Vault secrets backend and use_team_secrets_path enabled.

Background info

apache-airflow-providers-hashicorp is vulnerable to Authorization Bypass Through User-Controlled Key in versions 4.6.0 - 4.7.2.

How to fix this

Upgrade the apache-airflow-providers-hashicorp library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform