Vulnerability Description
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API output. Affects deployments that configure secrets backends via per-key environment overrides. Users are advised to upgrade to `apache-airflow` 3.3.0 or later.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | < 3.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/apache/airflow/pull/67622Issue Tracking
- https://lists.apache.org/thread/pq5yy40079h6tzh3fxvw28dd8dbk72hkVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/07/4Third Party Advisory
FAQ
What is CVE-2026-48892?
CVE-2026-48892 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRE...
How severe is CVE-2026-48892?
CVE-2026-48892 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48892?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Airflow.