CVE-2026-27173
8.7 HIGHJWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods
Published: 2026-05-19 · Last updated: 2026-05-19
Severity and scoring
- CVSS
- 8.7 HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
- CWE
- CWE-538
Description
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-50099 — During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed ... (4.6 MEDIUM)
- CVE-2026-50565 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (4.9 MEDIUM)
- CVE-2026-46617 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes
- CVE-2026-29114 — A vulnerability has been found in some Dahua products
- CVE-2019-25717 — Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated n... (4.3 MEDIUM)