Authorization Flaw in Apache Airflow Affects Multi-Team Deployments
CVE-2026-68971
Currently unrated
What is CVE-2026-68971?
An authorization flaw in Apache Airflow's asset materialization endpoint allows authenticated users in one team to trigger DAG runs of another team. This occurs due to the incorrect handling of team-specific permissions, which should restrict access based on the DAG resource. Instead, the authorization manager fails to consult the necessary team-scoped permissions, exposing XCom values and other sensitive data to unauthorized users. Users are encouraged to upgrade to Apache Airflow version 3.3.1 or later to mitigate this vulnerability.
Affected Version(s)
Apache Airflow 0 < 3.3.1