OVERVIEW CVE-2026-32690 affects Apache Airflow and involves improper redaction of sensitive data stored within JSON-formatted variables. When users retrieve variables containing nested secrets in JSON dictionary format, these sensitive fields fail to be properly masked, potentially exposing confidential information. Organizations using Airflow are only impacted if they store sensitive values in JSON variable structures; those utilizing alternative storage methods remain unaffected. Apache Airflow version 3.2.0 contains the implemented fix. SEVERITY The vulnerability carries a low CVSS score of 3.7, with a network-based attack vector requiring high complexity and no user interaction to exploit. The attack requires no privileges and poses a limited confidentiality impact while maintaining integrity and availability. The EPSS score of 0.000760000 indicates minimal prevalence relative to the broader CVE landscape, ranking higher than approximately 0.23 percent of all published vulnerabilities. EXPLOITATION STATUS There is no evidence of active exploitation, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on exploit tracking lists. No publicly available exploit code has been identified. The relatively low risk score of 28.0 on the FAUCET scale and negligible EPSS metrics suggest minimal community attention and low likelihood of weaponization. Organizations should prioritize patching based on their specific use of JSON variables rather than urgency driven by active threats.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.2.0CPE match | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.