CVE-2020-13927CISA KEVEPSS p100.0%

CVE-2020-13927Apache Airflow's Experimental API Authentication Bypass

Apache / Airflow's Experimental API

Description

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.

Scoring

EPSS99.70% probability of exploitation · percentile 100.0% · 2026-06-17T12:03:21Z

CISA KEV entry

Added to KEV: 2022-01-18

(incoming)1

TypeTargetConfidenceTier
KEVEntryApache Airflow's Experimental API Authentication Bypasskev-cve-2020-139270%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Apache Airflow Command Injection
CVE
CVE-2026-30911
CVE
CVE-2026-41017
CVE
CVE-2026-41014
CVE
CVE-2026-2095
CVE
CVE-2026-40961
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.