SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-33264

CRITICAL · CVSS 9.8 EPSS 0.99% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

A critical vulnerability in Apache Airflow allows attackers to exploit the `BaseSerialization.deserialize()` method, enabling remote code execution via malicious class paths embedded in serialized Directed Acyclic Graphs (DAGs). This breach compromises the security boundary by allowing unauthorized code execution within the API Server and Scheduler processes. Organizations using Apache Airflow, especially those with limited trust in DAG authors, should prioritize upgrading to version 3.3.0 or later and consider implementing strict deserialization class allowlists as a mitigation strategy.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-33264
Severity
CRITICAL
CVSS
9.8
EPSS
0.99%
Apache

Original NVD Description

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist.

Related CVEs

Other vulnerabilities affecting the same vendor(s)