LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-30898

CVE-2026-30898 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 20, 2026

Apache Airflow - Command Injection

Published: April 18, 2026Updated: April 20, 2026Remote Exploitable

Overview

Apache Airflow contains a command injection caused by unsanitized usage of dag_run.conf in BashOperator, letting UI users escalate privileges to execute code on worker, exploit requires crafted dag_run.conf input.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 2.6%(Probability of exploitation in next 30 days)

Impact

UI users can escalate privileges to execute arbitrary code on worker nodes, potentially compromising the system.

Mitigation

Review and sanitize dag_run.conf usage in DAGs; update to latest Airflow version with fixes.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 20, 2026

🟠 CVE-2026-30898 - High (8.8) An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30898/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 20, 2026

🟠 CVE-2026-30898 - High (8.8) An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30898/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-30898
Severity
High
CVSS Score
8.8
Type
command_injection
Status
unconfirmed
EPSS
2.6%
Social Posts
2

CWE

  • CWE-77

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

2.6%Probability of exploitation in the next 30 days