Authorization Flaw in Apache Airflow Affects Multi-Team Deployments
CVE-2026-68971

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68971?

An authorization flaw in Apache Airflow's asset materialization endpoint allows authenticated users in one team to trigger DAG runs of another team. This occurs due to the incorrect handling of team-specific permissions, which should restrict access based on the DAG resource. Instead, the authorization manager fails to consult the necessary team-scoped permissions, exposing XCom values and other sensitive data to unauthorized users. Users are encouraged to upgrade to Apache Airflow version 3.3.1 or later to mitigate this vulnerability.

Affected Version(s)

Apache Airflow 0 < 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@haoxucu
Jarek Potiuk
.