Executive brief
A security flaw in Apache Airflow's KubernetesExecutor causes sensitive authentication tokens (JWTs) to be exposed in plain text within Kubernetes pod configurations. An attacker with basic read-only access to the Kubernetes cluster could steal these tokens to impersonate a running task. This would allow them to unauthorizedly trigger or clear workflows, and read or modify sensitive business data such as Variables, Connections, and XComs.
Technical details
A vulnerability in Apache Airflow's KubernetesExecutor (CWE-538) causes JWT tokens used for Execution API authentication to be passed as command-line arguments to worker containers. These arguments are visible in the Kubernetes pod specification, making them accessible to any user with 'pods/get' permissions in the Airflow namespace. An attacker can harvest these tokens to call state-mutating Execution API endpoints, enabling them to trigger DAG runs, clear runs, or manipulate Variables, Connections, and XComs. This issue is the core-side component of a coordinated fix (alongside CVE-2026-27173). Users should upgrade to apache-airflow 3.2.2 or later.
Affected products
- Apache Airflow < 3.2.2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-01: patched