Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-34538— Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)

Quick assessment

Affected
Apache Software Foundation Apache Airflow
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Airflow是美国阿帕奇(Apache)基金会的一套具有创建、管理和监控工作流程功能的开源平台。该平台具有可扩展和动态监控等特点。 Apache Airflow 3.0.0至3.1.8版本存在安全漏洞,该漏洞源于DagRun等待端点向仅具有DAG运行读取权限的用户返回XCom结果值,这与FAB RBAC模型将XCom视为单独受保护资源以及安全模型文档将查看者角色定义为只读相冲突。

AI Predicted 5.3 Difficulty: Easy EPSS 0.79% · P55

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-34538

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
Source: CVE Program / CVE List V5
Vulnerability Description
Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model documentation that defines the Viewer role as read-only. Airflow uses the FAB Auth Manager to manage access control on a per-resource basis. The Viewer role is intended to be read-only by default, and the security model documentation defines Viewer users as those who can inspect DAGs without accessing sensitive execution results. Users are recommended to upgrade to Apache Airflow 3.2.0 which resolves this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
将资源暴露给错误范围
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Airflow 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Airflow是美国阿帕奇(Apache)基金会的一套具有创建、管理和监控工作流程功能的开源平台。该平台具有可扩展和动态监控等特点。 Apache Airflow 3.0.0至3.1.8版本存在安全漏洞,该漏洞源于DagRun等待端点向仅具有DAG运行读取权限的用户返回XCom结果值,这与FAB RBAC模型将XCom视为单独受保护资源以及安全模型文档将查看者角色定义为只读相冲突。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Airflow 3.0.0 ~ 3.2.0 -

II. Public POCs for CVE-2026-34538

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-34538

请登录查看更多情报信息。

Same Patch Batch · Apache Software Foundation · 2026-04-09 · 17 CVEs total

CVE-2026-34500 Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
CVE-2026-34487 Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer tok
CVE-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
CVE-2026-34483 Apache Tomcat: Incomplete escaping of JSON access logs
CVE-2026-32990 Apache Tomcat: Fix for CVE-2025-66614 is incomplete
CVE-2026-29146 Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
CVE-2026-29145 Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail i
CVE-2026-29129 Apache Tomcat: TLS cipher order is not preserved
CVE-2026-25854 Apache Tomcat: Occasionally open redirect
CVE-2026-24880 Apache Tomcat: Request smuggling via invalid chunk extension
CVE-2026-40046 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168
CVE-2026-33005 Apache OpenMeetings: Insufficient checks in FileWebService
CVE-2026-33266 Apache OpenMeetings: Hardcoded Remember-Me Cookie Encryption Key and Salt
CVE-2026-34020 Apache OpenMeetings: Login Credentials Passed via GET Query Parameters
CVE-2025-57735 Apache Airflow: Airflow Logout Not Invalidating JWT
CVE-2025-62188 Apache DolphinScheduler: Users can access sensitive information through the actuator endpo

IV. Related Vulnerabilities

V. Comments for CVE-2026-34538

No comments yet


Leave a comment