← Vulnerability feed

Vulnerability record · CVE-2021-38540 · published 9 September 2021

CVE-2021-38540: Apache Airflow variable import endpoint missing authentication

Apache · Airflow

The variable import endpoint in Apache Airflow 2.0.0 through 2.1.3 was not protected by authentication. Unauthenticated users could reach it to add or modify Airflow variables used in DAGs, which can lead to denial of service, information disclosure or remote code execution.

9.8 CVSS 3.1 Critical EPSS 81% · top 0.4% CWE-269 · Improper privilege managementCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS probability, allowing direct impact on confidentiality, integrity and availability.

What it is

The variable import endpoint in Apache Airflow 2.0.0 through 2.1.3 was not protected by authentication. Unauthenticated users could reach it to add or modify Airflow variables used in DAGs, which can lead to denial of service, information disclosure or remote code execution.

Impact

An unauthenticated attacker can alter Airflow variables that DAGs consume, enabling denial of service, disclosure of sensitive data, or remote code execution depending on how those variables are used.

Attack surface

Reachable over the network via the variable import endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.80938 (99.6th percentile), indicating substantial predicted exploitation activity.

What to do

  • Upgrade Apache Airflow to 2.1.3 or later, which is the fixed version per the advisory.
  • If immediate upgrade is not possible, restrict network access to the Airflow web interface and variable import endpoint to trusted networks only.
  • Enable authentication on the Airflow web server and verify that all API and import endpoints enforce it.
  • Audit Airflow variables for unauthorized additions or modifications and review DAGs that consume them.
  • Monitor for unexpected changes to variables that feed into code execution or credential handling paths.

Detection

  • Review Airflow web server and access logs for unauthenticated requests to the variable import endpoint.
  • Alert on creation or modification of Airflow variables outside expected change windows or by unexpected sources.
  • Monitor DAG behavior for anomalies tied to variable values, such as unexpected command execution or data access.
  • Correlate variable changes with subsequent process execution or outbound connections from Airflow workers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-38540 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-13927Apache Airflow Experimental API missing authentication by defaultAirflow's Experimental API defaulted to allowing all requests without authentication, so any reachable instance exposed its API to unauthenticated ca…KEVEPSS 100%analysed8.8CVE-2020-11978Apache Airflow example DAG command injectionApache Airflow 1.10.10 and below ship an example DAG containing an OS command injection flaw. Any authenticated user can execute arbitrary commands a…KEVEPSS 99%analysed9.8CVE-2026-33264Apache airflow deserialization of untrusted data vulnerabilityA bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server …EPSS 1.6%9.8CVE-2023-25754Apache airflow vulnerabilityPrivilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.EPSS 2.3%9.8CVE-2023-22884Apache airflow command injection vulnerabilityImproper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apach…EPSS 11%9.8CVE-2022-40189Apache airflow os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airfl…EPSS 4.1%9.8CVE-2022-38649Apache airflow os command injection vulnerabilityImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Air…EPSS 3.3%9.8CVE-2022-38054Apache airflow vulnerabilityIn Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2021-38540), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.