Junglewise Threat Intelligence

CVE-2026-34538: Apache Airflow authorization bypass in DagRun wait endpoint

CVE-2026-34538 · Severity: medium · CVSS 6.5 · Published 2026-04-09

Technologies: Apache Airflow, apache-airflow (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Airflow, a platform used to schedule and monitor workflows, contains a security flaw where users with restricted 'Viewer' access can view sensitive task execution data (XComs) they should not be able to see. This bypasses the intended security model which is supposed to keep execution results private from read-only users. An attacker with basic access to the system could use this to harvest sensitive information processed by your data pipelines.

Technical details

An authorization bypass exists in the Apache Airflow DagRun wait endpoint (CWE-668). The root cause is a missing permission check for 'RESOURCE_XCOM' when the 'result' parameter is specified in the DagRun wait API. This allows authenticated users with low-privilege 'Viewer' roles (who only possess DAG Run read permissions) to retrieve XCom execution results, which are intended to be protected resources. An attacker with network access and valid low-level credentials can exploit this to access sensitive data passed between tasks. The issue is resolved in Apache Airflow 3.2.0 by adding the necessary XCom permission validation to the affected endpoint.

Affected products

  • Apache Airflow >= 3.0.0, < 3.2.0

Timeline

  • 2026-03-30: patched: Fix merged into main branch
  • 2026-04-09: disclosed
  • 2026-04-09: advisory

References

Related threats