A notice attributed to Jarek Potiuk and published in the oss-sec feed on September 24, 2026 describes CVE-2026-97636, rated moderate. It concerns the Apache Airflow HashiCorp provider, specifically team-scope protection in the HashiCorp Vault secrets backend.
According to the text, a DAG author restricted to one team can supply a user-controlled variable key containing a path separator. This may cause the backend to resolve a secret belonging to another team. The available excerpt does not detail other conditions or the full mechanism.
The listed affected versions are Apache Airflow HashiCorp provider releases from 4.6.0 up to, but not including, 4.8.0. Consult the original notice in the oss-sec archive and official CVE records to verify scope, conditions, and update guidance before taking action.
Operators should check the installed version and review permissions and cross-team secret access. If using AI to summarize or apply the notice, share only the necessary text and remove credentials, personal names, and internal data; verify technical recommendations against the original notice.