A vulnerability marked as critical has been reported in Apache Airflow. Affected by this vulnerability is an unknown functionality of the component Backfill API. The manipulation leads to authorization bypass.

This vulnerability is referenced as CVE-2026-68968. Remote exploitation of the attack is possible. No exploit is available.