Authorization Flaw in Apache Airflow Affects User Task Log Access
CVE-2026-22922
6.5MEDIUM
What is CVE-2026-22922?
Apache Airflow versions 3.1.0 through 3.1.6 experience an authorization flaw that permits authenticated users with limited task access permissions to view task logs without proper privileges. This vulnerability exposes sensitive log information, creating potential security risks. It is advised for users to upgrade to Apache Airflow version 3.1.7 or later to mitigate this issue. For more information, please refer to the provided vendor advisory and patch notes.
Affected Version(s)
Apache Airflow 3.1.0 < 3.1.7