LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-27173

apache · apache-airflow-providers-cncf-kubernetes

Published
CVSS8.7
Severityhigh
WeaknessCWE-538
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Description

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-27173

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-27173.