LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-30911

apache · airflow

Published
CVSS8.1
Severityhigh
WeaknessCWE-862
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-30911

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-30911.