AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-68971

MEDIUM · CVSS 6.5 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects Apache Airflow's asset materialization endpoint and the XCom result check, allowing authenticated users from one team to trigger DAG runs and access XCom values belonging to other teams in multi-team deployments. This misconfiguration bypasses team-specific authorization, potentially leading to unauthorized data access and operational disruptions. Organizations using Apache Airflow in a multi-team environment should prioritize upgrading to version 3.3.1 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-68971
Severity
MEDIUM
CVSS
6.5
EPSS
0.33%
Apache

Original NVD Description

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by that field -- the Keycloak auth manager, for example, checks the `DAG` resource instead of `DAG:<team>` -- so the team-scoped permission that should gate the request was never consulted. In a deployment running multi-team mode with a team-aware auth manager, an authenticated user in one team could trigger Dag runs belonging to another team, supplying their own `dag_run_id` and `conf`, and could read another team's XCom values. Deployments using the FAB auth manager are unaffected, as it has no multi-team support. Users are advised to upgrade to apache-airflow 3.3.1 or later, which resolves the Dag's team at both sites.

Related CVEs

Other vulnerabilities affecting the same vendor(s)