Insufficient Granularity of Access Control Affecting apache-airflow-providers-google package, versions [,22.3.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.48% (40th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSGOOGLE-18677474
  • published12 Aug 2026
  • disclosed12 Aug 2026
  • creditApache Airflow security team

Introduced: 12 Aug 2026

NewCVE-2026-68868  (opens in a new tab)
CWE-1220  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-google to version 22.3.0 or higher.

Overview

apache-airflow-providers-google is a Provider for Apache Airflow. Implements apache-airflow-providers-google package

Affected versions of this package are vulnerable to Insufficient Granularity of Access Control in the google Secret Manager backend process. An attacker can access other teams' Connections and Variables by exploiting the lack of team scope enforcement.

Note: This is only exploitable if multi-team mode is enabled and the google Secret Manager backend is used.

CVSS Base Scores

version 4.0
version 3.1