Access Control Flaw in Apache Airflow API Allows Unauthorized Event Enumeration
CVE-2026-75158
Currently unrated
What is CVE-2026-75158?
The Apache Airflow API's '/assets/events' endpoint allows authenticated users with asset-read access to retrieve asset events associated with Dags they are not authorized to access. This flaw permits users to enumerate sensitive information, including DAG IDs and timestamps, which can expose the architecture and flow of workflows within the deployment. The lack of proper filters also leads to unintended disclosure of total entries and pagination details, empowering attackers to identify hidden Dags while circumventing access restrictions. Users are advised to upgrade to Apache Airflow version 3.3.2 or higher to mitigate this issue.
Affected Version(s)
Apache Airflow 0 < 3.3.2