CVE-2026-30911 PUBLISHED

Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

Assigner: apache
Reserved: 07.03.2026 Published: 17.03.2026 Updated: 17.03.2026

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance.

Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

Product Status

Vendor Apache Software Foundation
Product Apache Airflow
Versions Default: unaffected
  • affected from 3.1.0 to 3.1.8 (excl.)

Credits

  • Kai Aizen finder
  • Aritra Basu remediation developer

References

Problem Types

  • CWE-862 Missing Authorization CWE