Access Control Flaw in Apache Airflow UI Affects User Permissions
CVE-2026-41014

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 June 2026

What is CVE-2026-41014?

The partitioned_dag_runs endpoints within the Apache Airflow UI exhibit an access control issue where users with global Asset:read permissions can access and enumerate run states, schedule configurations, and asset wiring for Dags that they should not have access to. This vulnerability compromises the intended per-Dag read authorization when broader Asset permissions are granted, potentially exposing sensitive information to unauthorized users. It is recommended that affected installations upgrade to Apache Airflow version 3.2.2 or later to mitigate this issue.

Affected Version(s)

Apache Airflow 3.2.0 < 3.2.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yalguun Tumenkhuu (fg0x0)
Jarek Potiuk
.