Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore read, pause and cancel backfills belonging to any other Dag, including moving another Dag's queued runs to `failed`. No non-default configuration is required and backfill ids are sequential, so finding a target is trivial. Users are advised to upgrade to apache-airflow 3.3.1 or later, which parses the backfill id with the same type the routes declare.
🚨 HIGH: CVE-2026-68968 (CVSS 7.5) - Apache Airflow Backfill API authorization bypass. Authenticated users can read/pause/cancel backfills across ANY Dag. Upgrade to 3.3.1+ immediately. #CVE#Vulnerability#PatchNow#ThreatIntel https://t.co/16ENT2XzsL
🚨*CVE*
CVE-2026-68968 Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization … https://www.cve.org/CVERecord?id=CVE-2026-68968
-----
Traducción:
CVE-2026-68968 Apa… http://infoflow.cloud`
Post summary
The post announces a new Apache Airflow CVE, briefly explains the technical issue, and links to the official CVE record, but it does not provide PoC, exploit code, or remediation details.
CVE-2026-68968 Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization … https://www.cve.org/CVERecord?id=CVE-2026-68968
Post summary
Airflow’s Backfill API erroneously authorizes requests based on a caller‑supplied Dag ID whenever the backfill_id path segment cannot be parsed, exposing an authorization flaw.