PatchSiren cyber security CVE debrief
CVE-2026-49267 Apache Software Foundation CVE debrief
Apache Airflow's core email utilities fail to verify SMTP server certificates during STARTTLS negotiation, enabling network-positioned attackers to intercept credentials and message contents via forged certificates. This CVE addresses the core `apache-airflow` package, complementing the prior SMTP-provider fix in CVE-2026-41016 (2026-04-27). Affected configurations use `[email] smtp_starttls=True` without `[email] smtp_ssl` and expose SMTP traffic to less-trusted network segments.
- Vendor
- Apache Software Foundation
- Product
- Apache Airflow
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-01
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-06-01
- Advisory updated
- 2026-07-21
Who should care
Organizations running Apache Airflow with STARTTLS-enabled email configurations where SMTP relays traverse untrusted or semi-trusted networks, particularly those who applied the CVE-2026-41016 provider fix and assumed complete coverage.
Technical summary
When `[email] smtp_starttls=True` is configured without `[email] smtp_ssl`, Apache Airflow's `airflow.utils.email` helpers and the EmailOperator initiate STARTTLS but do not validate the remote SMTP server's certificate. A network MITM attacker can present an arbitrary certificate, complete the TLS handshake, and capture SMTP AUTH credentials plus email contents. The vulnerability exists in the core package separate from the SMTP provider path fixed under CVE-2026-41016. Resolution in apache-airflow 3.2.2 adds proper certificate verification to the STARTTLS code path.
Defensive priority
high
Recommended defensive actions
- Upgrade apache-airflow to version 3.2.2 or later to obtain certificate verification for STARTTLS connections in airflow.utils.email.
- If already patched for CVE-2026-41016 (apache-airflow-providers-smtp), confirm core package is also upgraded to 3.2.2+ as the provider fix does not cover the core utility path.
- Audit [email] configuration: if smtp_starttls=True and smtp_ssl=False, verify SMTP relay network path is either trusted or upgrade immediately.
- Review SMTP credentials for rotation if deployment was historically exposed to untrusted network segments.
- Monitor for unexpected certificate validation failures after upgrade, which may indicate previously accepted invalid certificates.
Evidence notes
CWE-295 (Certificate Validation Improper) assigned by [email protected]. Fix implemented in GitHub pull request. Apache security mailing list thread published. NVD status 'Undergoing Analysis' as of source capture.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49267 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49267
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49267 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49267
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/apache/airflow/pull/65346
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/6v2ds757000msmjmovnnqryqzks83ps0
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.