CVE-2026-30911
Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
| CWE | CWE-862 |
| Vendor | apache software foundation |
| Product | apache airflow |
| Published | Mar 17, 2026 |
| Last Updated | Mar 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache airflow
Be the first to know when new high vulnerabilities affecting apache software foundation apache airflow are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Airflow
3.1.0 < 3.1.8
References
Credits
Kai Aizen Aritra Basu