CVE-2026-27173 - CERT CVE
ID CVE-2026-27173
Sažetak JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
Reference
CVSS
Base: 8.7
Impact: 6.0
Exploitability:2.0
Pristup
VektorSloženostAutentikacija
LOCAL LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Zadnje važnije ažuriranje 19-05-2026 - 21:16
Objavljeno 19-05-2026 - 20:16