Authorization Flaw in Apache Airflow Affects Multiple Versions
CVE-2026-26929
6.5MEDIUM
What is CVE-2026-26929?
The FastAPI DagVersion listing API in Apache Airflow versions 3.0.0 through 3.1.7 does not implement proper per-DAG authorization filtering when requests are made with a wildcard dag_id ('~'). This allows unauthorized users to access metadata for DAGs that they are not permitted to view, exposing sensitive information. It is crucial for users to upgrade to Apache Airflow version 3.1.8 or later to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Airflow 3.0.0 < 3.1.8
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pierre Jeambrun