PT-2026-71130 · Apache · Apache Airflow

·

CVE-2026-68968

·

Published

2026-08-12

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.3.1
Description An authorization flaw exists in the Backfill API where a discrepancy in how the backfill id path segment is parsed allows an authenticated user with edit permissions on any single Dag to perform unauthorized actions on other Dags. The authorization dependency uses int() for parsing, while the route handler uses pydantic's NonNegativeInt, which accepts values that int() rejects (for example, 1.0 is coerced to 1). Because FastAPI resolves dependencies before endpoint validation, the authorization check and the actual operation act on different Dags. This allows users to read, pause, and cancel backfills of other Dags, or move queued runs to a failed state. Since backfill ids are sequential, identifying targets is trivial.
Recommendations Upgrade to version 3.3.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-68968
CVE-2026-68968
PYSEC-2026-3710

Affected Products

Apache Airflow