Junglewise Threat Intelligence

CVE-2026-80049: Airbyte Platform workspace authorization bypass

CVE-2026-80049 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Airbyte Platform.

Executive brief

Airbyte Platform is a data integration platform that manages connections and syncs between data sources and destinations. This vulnerability allows members of one workspace to gain unauthorized access to resources (connections, sources, destinations) in other workspaces by manipulating request parameters. An attacker can read sensitive configuration data, trigger or cancel syncs, and delete resources across workspaces without proper authorization.

Technical details

The vulnerability is an authorization bypass in the AuthenticationHeaderResolver component, which resolves the workspace used for authorization decisions based on a caller-supplied X-Airbyte-Workspace-Id header rather than deriving it from the actual resource being accessed. The AuthorizationServerHandler extracts workspace identifiers from the JSON request body and injects them into headers, but the permission check uses the caller's nominated workspace instead of verifying that the resource actually belongs to that workspace. Endpoints can be reached with an attacker-supplied workspaceId field that bypasses the declared request schema validation. The vulnerability requires network access to the Airbyte API and can be exploited by any authenticated workspace member, allowing them to perform operations on resources in other workspaces without proper access control. No patch availability information is provided in the advisory.

Affected products

  • Airbyte Platform v2.0.0 and likely earlier versions

Timeline

  • 2026-08-25: disclosed

References