EXPOSURES › CVE-2020-13927
CVE-2020-13927
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Airflow's default experimental API allowed unauthenticated access, enabling attackers to bypass authentication and execute arbitrary commands.
The default configuration of Apache Airflow's Experimental API permitted all API requests without authentication, allowing attackers to bypass security controls and execute arbitrary commands. This failure is critical for DIB organizations because it represents a negligent default that directly enables remote code execution and data exfiltration, violating NIST 800-171 requirements for access control and system integrity. Organizations must ensure that all software defaults are hardened before deployment and that experimental features are disabled by default.
Shame score — The vendor shipped a widely-used workflow orchestration tool with a default configuration that completely bypassed authentication, allowing unauthenticated attackers to execute arbitrary commands and access sensitive data.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.