CVE-2026-30898 Details
Description
An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advice.
A vulnerability exists in Apache Airflow versions prior to 3.2.0, where an example in the documentation incorrectly suggested how to use the BashOperator with Jinja templating. This could lead to unsanitized user input being used to escalate the privileges of a UI user, allowing them to execute code on a worker. Users are advised to check their own Directed Acyclic Graphs (DAGs) for adherence to this flawed guidance.
Users should update to Apache Airflow version 3.2.0 or later. For those who have followed the incorrect documentation example, review and revise the affected DAGs to ensure they do not introduce this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/04/17/7 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/airflow/pull/64129 | [email protected] | Issue Tracking |
| https://lists.apache.org/thread/26zmhfj1t95c1hld2r14ho81nzh1bdc8 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache airflow | < 3.2.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | CVE Modified | CISA-ADP |
| Apr 18, 2026 | New CVE Received | [email protected] |
| Apr 18, 2026 | CVE Modified | CVE |