


Perceptive Security
SOC/SIEM Consultancy

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authen…
Published:
16 maart 2026 om 23:00:00
Alert date:
17 maart 2026 om 16:02:36
Source:
nvd.nist.gov
Enterprise Applications, Identity & Access
Apache Airflow versions 3.1.0 through 3.1.7 contain a missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints. This vulnerability allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance, representing a privilege escalation issue. The vulnerability affects the workflow orchestration system's access control mechanisms. Users are advised to upgrade to Apache Airflow version 3.1.8 or later to resolve this security issue.
Technical details
Mitigation steps:
Affected products:
Apache Airflow
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-30911
https://github.com/apache/airflow/pull/62886
https://lists.apache.org/thread/1rs2v7fcko2otl6n9ytthcj87cmsgx51
http://www.openwall.com/lists/oss-security/2026/03/17/2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
