← Back to CVE List
Vulnerability Intelligence Report
Apache Airflow's Experimental API Authentication Bypass

CVE-2020-13927

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:99.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-306 ↗CWE-306 Missing Authentication for Critical Function
CWE-1188 ↗CWE-1188 Initialization of a Resource with an Insecure Default
CWE-1056 ↗CWE-1056 Invokable Control Element with Variadic Parameters

Affected Products & Versions

Vendor Product Affected Versions
apache airflow all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.700%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApache Software Foundation · Vendor · USA
Reserved2020-06-08T00:00:00
Published2020-11-10T00:00:00
Last Updated2025-10-21T23:35:32

LINK COPIED TO CLIPBOARD