PT-2026-31598 · Apache · Apache Airflow
Kevin Yang
+1
·
Published
2026-04-09
·
Updated
2026-04-13
·
CVE-2026-34538
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions 3.0.0 through 3.1.8
Description
The DagRun wait endpoint in Apache Airflow allows users with DAG Run read permissions, such as the Viewer role, to access XCom result values. This behavior contradicts the intended security model where XCom is a protected resource and the Viewer role should be read-only.
Recommendations
Upgrade to Apache Airflow version 3.2.0.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow