CVE-2026-58076
Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server
Description
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.
INFO
Published Date :
Aug. 12, 2026, 4:17 p.m.
Last Modified :
Sept. 16, 2026, 3:17 p.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | [email protected] | ||||
| CVSS 3.1 | HIGH | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
Solution
- Upgrade Apache Airflow to version 3.3.1 or later.
- Restrict imported classes to subclasses of BaseException.
- Ensure deserialization does not invoke arbitrary callables.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-58076.
| URL | Resource |
|---|---|
| https://github.com/apache/airflow/pull/68511 | Issue Tracking Patch |
| https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos | Mailing List Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-33264 | Not Applicable |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-58076 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-58076
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-58076 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-58076 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by [email protected]
Sep. 16, 2026
Action Type Old Value New Value Added Affected Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/58xxx/CVE-2026-58076.json">CVE-2026-58076</a> Added Reference https://github.com/apache/airflow/pull/68511 Added Reference https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos Added Reference https://www.cve.org/CVERecord?id=CVE-2026-33264 Removed Reference https://github.com/apache/airflow/pull/68511 Removed Reference https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos Removed Reference https://www.cve.org/CVERecord?id=CVE-2026-33264 Removed Reference Type https://github.com/apache/airflow/pull/68511 Types: Issue Tracking, Patch Removed Reference Type https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos Types: Mailing List, Vendor Advisory Removed Reference Type https://www.cve.org/CVERecord?id=CVE-2026-33264 Types: Not Applicable -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Aug. 18, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Added SSVC {'id': 'CVE-2026-58076', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-08-18T13:43:21.351742Z'} -
Initial Analysis by [email protected]
Aug. 14, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Added CPE Configuration OR *cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* versions from (including) 3.3.0 up to (excluding) 3.3.1 Added Reference Type Apache Software Foundation: https://github.com/apache/airflow/pull/68511 Types: Issue Tracking, Patch Added Reference Type Apache Software Foundation: https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos Types: Mailing List, Vendor Advisory Added Reference Type Apache Software Foundation: https://www.cve.org/CVERecord?id=CVE-2026-33264 Types: Not Applicable -
New CVE Received by [email protected]
Aug. 12, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Apache Software Foundation', 'product': 'Apache Airflow', 'versions': [{'status': 'affected', 'version': '3.0.0', 'lessThan': '3.3.1', 'versionType': 'semver'}], 'packageName': 'apache-airflow', 'collectionURL': 'https://pypi.python.org', 'defaultStatus': 'unaffected'}] Added Description Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`. Added CWE CWE-502 Added Reference https://github.com/apache/airflow/pull/68511 Added Reference https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos Added Reference https://www.cve.org/CVERecord?id=CVE-2026-33264