CVE-2026-30911
Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
8.1
HIGH
CVSS 3.1
EPSS 0.04%
Description
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
How to fix CVE-2026-30911
To remediate CVE-2026-30911, upgrade the affected package to a fixed version below.
- —upgrade to 3.1.8 or later
- —upgrade to 3.1.8 or later
- —upgrade to 3.1.8 or later
Is CVE-2026-30911 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 3.1.0, < 3.1.8
- >= 3.0.0, < 3.1.8
- >= 3.1.0, < 3.1.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |