CVE-2026-30911

CVE-2026-30911: Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-862 · Missing authorization
Published March 17, 2026
Last update March 17, 2026

CVSS base score

What the vulnerability does

Description

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

Key dates

Disclosure timeline

March 17, 2026 CVE published
March 17, 2026 Record updated