PT-2026-25893 · Apache · Apache Airflow

Aritra Basu

+1

·

Published

2026-03-17

·

Updated

2026-03-18

·

CVE-2026-30911

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.1.0 through 3.1.7
Description Apache Airflow versions 3.1.0 through 3.1.7 contain a missing authorization issue within the Human-in-the-Loop (HITL) endpoints of the Execution API. This allows any authenticated task instance to perform actions—reading, approving, or rejecting—on HITL workflows belonging to other task instances. The HITL endpoints are part of the Execution API, which manages the execution of tasks within Airflow workflows. The issue stems from a lack of proper access controls, enabling unauthorized access and manipulation of HITL workflows.
Recommendations Upgrade to Apache Airflow version 3.1.8 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-05615
BIT-AIRFLOW-2026-30911
CVE-2026-30911
GHSA-8X34-9Q3V-H7G8
PYSEC-2026-17

Affected Products

Apache Airflow