CVE-2021-26559 - CVE House
Back to Database
Status published Medium CVE-2021-26559

CWE-284 Improper Access Control on Configurations Endpoint for the Stable API

Vulnerability Description

Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow.cfg`. This allowed a privilege escalation attack. This issue affects Apache Airflow 2.0.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-26559

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Apache Airflow would like to thank Ian Carroll for reporting this issue.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Airflow
Vulnerable Versions:
Apache Airflow 2.0.0

Timeline

Official Publish: February 17th, 2021
Last Modified: February 13th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)