Access Control Flaw in Apache Airflow Affects Viewer Role Permissions
CVE-2026-34538

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 April 2026

What is CVE-2026-34538?

The DagRun wait endpoint in Apache Airflow versions 3.0.0 through 3.1.8 incorrectly exposes XCom result values to users with the Viewer role. This role is designed for read-only access, yet users unnecessarily gain visibility into sensitive execution results, violating the intended security model. This issue compromises the FAB RBAC model, which treats XCom as a protected resource. Users are urged to upgrade to Apache Airflow 3.2.0 to rectify this vulnerability.

Affected Version(s)

Apache Airflow 3.0.0 < 3.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

selen
Kevin Yang
.