๐Ÿ” CVE Alert

CVE-2026-30911

HIGH 8.1

Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

CWE CWE-862
Vendor apache software foundation
Product apache airflow
Published Mar 17, 2026
Last Updated Mar 17, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow

Be the first to know when new high vulnerabilities affecting apache software foundation apache airflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow
3.1.0 < 3.1.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/62886 lists.apache.org: https://lists.apache.org/thread/1rs2v7fcko2otl6n9ytthcj87cmsgx51 openwall.com: http://www.openwall.com/lists/oss-security/2026/03/17/2

Credits

Kai Aizen Aritra Basu