Vulnerability record · CVE-2021-38540 · published 9 September 2021
CVE-2021-38540: Apache Airflow variable import endpoint missing authentication
Apache · Airflow
The variable import endpoint in Apache Airflow 2.0.0 through 2.1.3 was not protected by authentication. Unauthenticated users could reach it to add or modify Airflow variables used in DAGs, which can lead to denial of service, information disclosure or remote code execution.
Description
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code execution. This issue affects Apache Airflow >=2.0.0, <2.1.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a very high EPSS probability, allowing direct impact on confidentiality, integrity and availability.
What it is
The variable import endpoint in Apache Airflow 2.0.0 through 2.1.3 was not protected by authentication. Unauthenticated users could reach it to add or modify Airflow variables used in DAGs, which can lead to denial of service, information disclosure or remote code execution.
Impact
An unauthenticated attacker can alter Airflow variables that DAGs consume, enabling denial of service, disclosure of sensitive data, or remote code execution depending on how those variables are used.
Attack surface
Reachable over the network via the variable import endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high at 0.80938 (99.6th percentile), indicating substantial predicted exploitation activity.
What to do
- Upgrade Apache Airflow to 2.1.3 or later, which is the fixed version per the advisory.
- If immediate upgrade is not possible, restrict network access to the Airflow web interface and variable import endpoint to trusted networks only.
- Enable authentication on the Airflow web server and verify that all API and import endpoints enforce it.
- Audit Airflow variables for unauthorized additions or modifications and review DAGs that consume them.
- Monitor for unexpected changes to variables that feed into code execution or credential handling paths.
Detection
- Review Airflow web server and access logs for unauthenticated requests to the variable import endpoint.
- Alert on creation or modification of Airflow variables outside expected change windows or by unexpected sources.
- Monitor DAG behavior for anomalies tied to variable values, such as unexpected command execution or data access.
- Correlate variable changes with subsequent process execution or outbound connections from Airflow workers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-38540 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-38540), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.