Unauthorized Data Exposure in Apache Airflow by Apache
CVE-2026-24098
6.5MEDIUM
What is CVE-2026-24098?
Apache Airflow versions prior to 3.1.7 have a vulnerability that permits authenticated users, who have permissions for specific Directed Acyclic Graphs (DAGs), to access import errors of other DAGs they are not authorized to view. This flaw could lead to the unauthorized disclosure of sensitive error information. Users of Apache Airflow should update their installations to version 3.1.7 or later to mitigate this issue.
Affected Version(s)
Apache Airflow 3.0.0 < 3.1.7