CVE-2026-30911Disclosure(apache / airflow)

LOWCVSS 8.1 · HIGH

Signal is active with 7 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 7 mentions across 1 observed day

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • 7 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline7 mentions / 1d
02457Mentions · 2026-03-17: 7Technical Details · 2026-03-17: 503-17
Signal classification2 categories
Disclosure
457.1%
General
342.9%
Referenced assets8 URLs
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    General

    4 CVEs in Apache Airflow CVE-2026-30911: Execution API HITL Endpoints Missing Per-Task Authorization https://www.openwall.com/lists/oss-security/2026/03/17/2 CVE-2026-28779: Path of session token in cookie does not consider base_url - session hijacking https://www.openwall.com/lists/oss-security/2026/03/17/3 + next tweet

    Post summary

    The tweet lists two Apache Airflow CVEs with brief descriptions and links to further discussion, but provides no evidence of exploitation, patches, or PoC code.

    100601.0K
    4.4K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-30911 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-30911 #CVE-2026-30911 #CVE  #Apache #CyberSecurity #InfoSec https://t.co/gKR9s9ipct

    Post summary

    A tweet announces a new CVE (CVE-2026-30911) affecting Apache with an unknown risk level, but provides no further technical details, patches, or exploitation information.

    0001042
    101 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30911 - High Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, ... https://www.thehackerwire.com/vulnerability/CVE-2026-30911/ https://t.co/GvovhoUzd5

    Post summary

    The tweet announces a high‑severity missing authorization issue in Apache Airflow 3.1.0‑3.1.7, detailing that authenticated task instances can read protected data, with no mention of PoC, exploitation, or patch information.

    0000053
    138 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30911 Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticate… https://www.cve.org/CVERecord?id=CVE-2026-30911

    Post summary

    The tweet succinctly announces a missing authorization flaw in Apache Airflow’s Execution API HITL endpoints, providing only the CVE reference without any PoC, exploit, or remediation details.

    00000132
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30911 - Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization Intel Report: https://ift.tt/HwBtfv3

    Post summary

    An alert highlights CVE-2026-30911, noting a missing per‑task authorization on Apache Airflow’s Execution API HITL endpoints, and directs readers to an intel report.

    0000041
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30911 - Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization Intel Report: https://ift.tt/6PFsjof

    Post summary

    The post announces the new CVE-2026-30911 in Apache Airflow, noting missing per‑task authorization in Execution API endpoints, and links to an intel report but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000037
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-30911 Authorization Bypass in Apache Airflow 3.1.0-3.1.7 Human-in-the-Loop Endpoints https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30911

    Post summary

    The text references CVE‑2026‑30911 with a headline and a link to a vulnerability details page but provides no additional exploit, patch, or technical information.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more