Authorization Bypass Through User-Controlled Key Affecting apache-airflow-providers-yandex package, versions [,4.5.1rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSYANDEX-18609773
  • published11 Aug 2026
  • disclosed10 Aug 2026
  • creditApache Airflow security team

Introduced: 10 Aug 2026

NewCVE-2026-68871  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-yandex to version 4.5.1rc1 or higher.

Overview

apache-airflow-providers-yandex is a Provider package apache-airflow-providers-yandex for Apache Airflow

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the LockboxSecretBackend get_conn_value and get_variable lookups in airflow/providers/yandex/secrets/lockbox.py. An attacker can retrieve another team’s Lockbox Connection or Variable by supplying an ID that spells out that team’s namespace while running in multi-team mode, causing the backend to fall through to the team-agnostic lookup and return the secret’s value. This exposes the target team’s credentials to a caller from a different team and breaks secret isolation for deployments using the Yandex Lockbox secrets backend.

CVSS Base Scores

version 4.0
version 3.1