PT-2026-25893 · Apache · Apache Airflow

·

CVE-2026-30911

·

Published

2026-03-17

·

Updated

2026-03-18

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.1.0 through 3.1.7
Description Apache Airflow versions 3.1.0 through 3.1.7 contain a missing authorization issue within the Human-in-the-Loop (HITL) endpoints of the Execution API. This allows any authenticated task instance to perform actions—reading, approving, or rejecting—on HITL workflows belonging to other task instances. The HITL endpoints are part of the Execution API, which manages the execution of tasks within Airflow workflows. The issue stems from a lack of proper access controls, enabling unauthorized access and manipulation of HITL workflows.
Recommendations Upgrade to Apache Airflow version 3.1.8 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05615
BIT-AIRFLOW-2026-30911
CVE-2026-30911
ECHO-39C3-26FF-F15B
GHSA-8X34-9Q3V-H7G8
PYSEC-2026-17

Affected Products

Apache Airflow