CVE-2026-49298
Apache Software Foundation Apache Airflow, airflow
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. `pods/get` in the Airflow namespace) could harvest the JWT from `kubectl describe pod` output and then call state-mutating Execution API endpoints — triggering Dag runs, clearing runs, reading or writing Variables / Connections / XComs — as if they were a running task. Affects deployments using the `...
- CVSS
- 8.8
- EPSS
- 0.49% 39.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.01