Authorization Flaw in Apache Airflow Affects Multi-Team Deployments
CVE-2026-68971
6.5MEDIUM
What is CVE-2026-68971?
An authorization flaw in Apache Airflow's asset materialization endpoint allows authenticated users in one team to trigger DAG runs of another team. This occurs due to the incorrect handling of team-specific permissions, which should restrict access based on the DAG resource. Instead, the authorization manager fails to consult the necessary team-scoped permissions, exposing XCom values and other sensitive data to unauthorized users. Users are encouraged to upgrade to Apache Airflow version 3.3.1 or later to mitigate this vulnerability.
Affected Version(s)
Apache Airflow 0 < 3.3.1