Improper access control in Apache Airflow - CVE-2026-34538
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the DagRun wait endpoint when handling requests for DagRun wait results. A remote user can retrieve XCom result values to disclose sensitive information.
The issue affects users with DAG Run read permissions, such as the Viewer role, who should not be able to access XCom as a separate protected resource.