CVE-2026-34538Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model documentation that defines the Viewer role as read-only. Airflow uses the FAB Auth Manager to manage access control on a per-resource basis. The Viewer role is intended to be read-only by default, and the security model documentation defines Viewer users as those who can inspect DAGs without accessing sensitive execution results. Users are recommended to upgrade to Apache Airflow 3.2.0 which resolves this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 2Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-102
General2
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    General

    CVE-2026-34538: Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) https://www.openwall.com/lists/oss-security/2026/04/09/9 CVE-2025-57735: Apache Airflow: Airflow Logout Not Invalidating JWT https://www.openwall.com/lists/oss-security/2026/04/09/16 Both are "Severity: low"

    Post summary

    The text lists two low‑severity Apache Airflow CVEs with short descriptors and links, but provides no PoC, exploit, patch, or active‑exploitation information.

    01050737
    4.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-34538 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34538 #CVE-2026-34538 #CVE #Apache #CyberSecurity #InfoSec https://t.co/ZHZvjDSfdC

    Post summary

    The tweet simply announces the existence of CVE-2026-34538 for Apache with no technical details, exploitation information, or remediation steps.

    0000031
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34538 Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer r… https://www.cve.org/CVERecord?id=CVE-2026-34538 ----- Traducción: CVE-2026-34538 Apa… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑34538, noting that Apache Airflow 3.0.0–3.1.8’s DagRun wait endpoint leaks XCom results to users with only read permissions.

    0000035
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34538 Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer r… https://www.cve.org/CVERecord?id=CVE-2026-34538

    Post summary

    The tweet announces CVE-2026-34538, revealing that Apache Airflow's DagRun wait endpoint unintentionally exposes XCom result values to users with only read access.

    00000274
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more