[NEW] [medium] Apache Airflow: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Apache Airflow to execute arbitrary program code, bypass security measures, and disclose information.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to execute arbitrary program code, bypass security measures, and disclose information.
- Who is affected
- Deployments of Apache Airflow.
- Urgency
- Medium urgency as the vulnerabilities can lead to significant security breaches.
- Action
- Update to the latest version of Apache Airflow to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Airflow
Get an email when a new Airflow advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2223
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-488280.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-488910.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-494870.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-332640.99% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-488920.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-492960.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48828 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48891 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49487 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-33264 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48892 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49296 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumGHSA-4fh7-7jx4-8f6c: apache-airflow DAG source authorization bypass exposes co-located DAG sourceghsa
- mediumCVE-2026-49487: In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned …nvd
- mediumCVE-2026-49296: Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of ot…nvd
- mediumCVE-2026-48892: The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment varia…nvd
- mediumCVE-2026-48891: A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's re…nvd
- mediumCVE-2026-48828: The Bulk Variables API in Apache Airflow called the redactor without passing the variable's ke…nvd
- criticalCVE-2026-33264: A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-…nvd
Recent advisories for Apache Airflow
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Apache Airflow: Multiple vulnerabilitiescert-bund · 2026-08-13
- mediumCVE-2026-68971: Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`)…nvd · 2026-08-12
- mediumCVE-2026-68970: Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, …nvd · 2026-08-12
- mediumCVE-2026-68969: Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in clear…nvd · 2026-08-12
- highCVE-2026-68968: Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whe…nvd · 2026-08-12
- mediumCVE-2026-68076: Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Var…nvd · 2026-08-12
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25