PT-2026-25893 · Apache · Apache Airflow

Aritra Basu

+1

·

Publicado

2026-03-17

·

Atualizado

2026-03-18

·

CVE-2026-30911

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.1.0 through 3.1.7
Description Apache Airflow versions 3.1.0 through 3.1.7 contain a missing authorization issue within the Human-in-the-Loop (HITL) endpoints of the Execution API. This allows any authenticated task instance to perform actions—reading, approving, or rejecting—on HITL workflows belonging to other task instances. The HITL endpoints are part of the Execution API, which manages the execution of tasks within Airflow workflows. The issue stems from a lack of proper access controls, enabling unauthorized access and manipulation of HITL workflows.
Recommendations Upgrade to Apache Airflow version 3.1.8 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05615
BIT-AIRFLOW-2026-30911
CVE-2026-30911
GHSA-8X34-9Q3V-H7G8
PYSEC-2026-17

Produtos afetados

Apache Airflow