The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an external data producer distinct from the trusted DAG author — could write
Apache HTTP Server
Exploit
CVE-2026-49818
NVD
Refer to CVE-2026-49818 NVD advisory